Skip to main content
PCI-DSS-COMPLIANCE4 MIN READ

Compensating Control or Not?

Distinguish compensating controls from weak workarounds and ordinary remediation plans.

Classify each workaround claim. Potential compensating control Temporary remediation plan or risk acceptance Unacceptable substitute Legacy admin protocol cannot be disabled, but access is restricted to a hardened jump host, allow-listed admin group, session recording, daily log review, and vendor upgrade date Unsupported file-permission control is offset by immutable deployment image, file integrity monitoring, no shell access, and documented validation tests Critical patch delayed two weeks with owner, business reason, compensating network block, and scheduled fix window MFA rollout slips 10 days with named users, approved risk acceptance, daily account review, and final rollout date Unsupported encryption setting remains because…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us