# What is a Compensating Control?

> A compensating control is an alternative security or privacy safeguard used in place of a prescribed or selected control when the original cannot reasonably be implemented.

- Canonical URL: https://yellowcube.eu/glossary/compensating-control/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It should provide equivalent or comparable protection for the relevant objective in the system’s actual environment, and its use should be justified by constraints, threat analysis, and accepted risk — not convenience alone.

One replacement may require several coordinated controls. The organization should identify the original control’s intended outcome, compare the alternative’s coverage and strength, document dependencies and residual gaps, obtain any required approval, and reassess the decision as the system and threat environment change.

### Key points

- **Substitution justification:** Record why the original control is infeasible or unsuitable, which requirement and risk are involved, and why the proposed alternative is appropriate.
- **Equivalence:** Map mechanisms and procedures to the intended outcome, examine failure and bypass paths, and collect evidence that the full combination operates as designed.
- **Exception governance:** Assign ownership, approval, review dates, monitoring, and conditions for returning to the original control or adopting a better alternative.
- **Important limitation:** Calling a measure “compensating” does not make its protection equivalent. Documentation, approval, or audit acceptance is limited evidence, and another law, standard, customer, or authority may apply different substitution criteria.

### Related terms

[Security architecture](<https://yellowcube.eu/glossary/security-architecture/>) · [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Access control](<https://yellowcube.eu/glossary/access-control/>)

### Sources

[NIST, Compensating Controls](https://csrc.nist.gov/glossary/term/compensating_controls) · [NIST SP 800-53B, Control Baselines for Information Systems and Organizations](https://csrc.nist.gov/pubs/sp/800/53/b/upd1/final) · [NIST Risk Management Framework, Select Step FAQs](https://csrc.nist.gov/CSRC/media/Projects/Risk-Management/documents/03-Select%20Step/NIST%20RMF%20Select%20Step-FAQs.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

