Compensating Control
Definition
A security measure that reduces risk when the ideal control cannot be applied immediately. For example, routing traffic through a monitored proxy while a vulnerable service awaits patching. Compensating controls are by definition temporary.
- Field
- Incident response and IT security hardening
- Nature
- Interim risk-reduction measure
- Example
- Monitored proxy while a vulnerable service awaits patching
- Key property
- Temporary by definition
Common questions
Why is a compensating control described as temporary rather than a permanent fix?+
It addresses risk from a control gap without eliminating the underlying vulnerability, so it remains in place only until the ideal control, such as a patch or configuration fix, can be applied; leaving it in place indefinitely without remediating the root cause is considered poor practice.
How does an organisation decide a compensating control is adequate?+
It typically documents the residual risk the control leaves unaddressed, gets sign-off from a risk owner, and sets a target date for the permanent fix, since regulators and auditors generally expect compensating controls to be justified and time-bound rather than open-ended.
Related terms
- Access Revocation
- The removal of permissions, accounts, or trust relationships that the attacker exploited or could exploit. Distinct from credential rotation in that it...
- Attack Surface Reduction
- The systematic elimination of pathways an attacker could use to enter or move within a system. In incident response this includes closing...
- Credential Rotation
- The process of invalidating and replacing passwords, API keys, certificates, and other authentication tokens that may have been exposed during an incident....
- Long-Term Containment
- The incident response phase in which emergency stabilisation measures are replaced with durable controls, such as patches, credential rotation, and firewall changes,...
- System Hardening
- Configuration changes that reduce a system's attack surface by disabling unnecessary services, applying least-privilege access, enabling audit logging, and removing or restricting...