It should provide equivalent or comparable protection for the relevant objective in the system’s actual environment, and its use should be justified by constraints, threat analysis, and accepted risk — not convenience alone.
One replacement may require several coordinated controls. The organization should identify the original control’s intended outcome, compare the alternative’s coverage and strength, document dependencies and residual gaps, obtain any required approval, and reassess the decision as the system and threat environment change.
Key points
Substitution justificationRecord why the original control is infeasible or unsuitable, which requirement and risk are involved, and why the proposed alternative is appropriate.
EquivalenceMap mechanisms and procedures to the intended outcome, examine failure and bypass paths, and collect evidence that the full combination operates as designed.
Exception governanceAssign ownership, approval, review dates, monitoring, and conditions for returning to the original control or adopting a better alternative.
Important limitationCalling a measure “compensating” does not make its protection equivalent. Documentation, approval, or audit acceptance is limited evidence, and another law, standard, customer, or authority may apply different substitution criteria.