Skip to content

Compensating Control

What is Compensating Control?

An alternative security measure employed when a primary control cannot be implemented. Must provide an equivalent level of protection and be documented with justification.

Information Security

What the standards actually require on compensating control

Requirements naming compensating control across 6 standards, quoted from the control text.

Operate OT supply chain + asset lifecycle + physical security per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. OT Supply Chain Security must (a) qualify OT vendors and suppliers per NIST SP 800-161 Supply Chain Risk Management tailored to OT (vendor cybersecuri...

NISTSP82-8 · OT Supply Chain Security, Asset Lifecycle, and Physical Security
API 11641 control

Identify, evaluate, and apply patches and compensating controls to SCADA assets following risk-based prioritization.

API1164-09 · Patch and Vulnerability Management

When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.

ISM-1809 · When applications, operating systems, network devices or networked IT equipment that are n

Detect insecure services and protocols at operating system, application and package layers and disable them, applying compensating controls where they cannot be disabled.

ASBv3-NS-8 · Detect and disable insecure services and protocols

Restrict traffic between environments to authenticated and authorised connections, encrypt and monitor it, and review the configuration at least annually with a written justification for every allowed service, protocol, port and compensating control.

CCM-IVS-03 · Network Security

Questions people ask about compensating control

What is Compensating Control?
An alternative security measure employed when a primary control cannot be implemented. Must provide an equivalent level of protection and be documented with justification.
Why is Compensating Control important for compliance?
Compensating Control is a key concept in Information Security. Understanding compensating control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Compensating Control?
Key concepts related to Compensating Control include Control. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Compensating Control?
Compensating Control appears in the requirement text of IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security, API 1164, Australian Information Security Manual, Azure Security Benchmark. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Compensating Control?
Explore our compliance framework pages to see how compensating control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Compensating Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.