compensating security control

compensating security control

A management, operational, and/or technical control (i.e., safeguard or countermeasure) employed by an organization in lieu of a recommended security control in the low, moderate, or high baselines that provides equivalent or comparable protection for an information system.

📚 Reference: NIST SP 800-30 Rev. 1
🏷️ Category: Cybersecurity
📊 Commonality: common