A technical team investigating possible controls concludes that the most preferred control cannot be implemented as a result of too many constraints and decides to propose the second-best control. How is this control being referred to?
A compensating control is an alternative control implemented when the preferred control cannot be applied due to constraints (e.g., technical, financial, or operational). According to frameworks like COBIT or ISO/IEC 27001, compensating controls provide equivalent or partial risk mitigation when the primary control is infeasible.
Deterrent controls (A) discourage violations, detective controls (C) identify incidents, and corrective controls (D) address issues after they occur. Only compensating control (B) fits the scenario of a second-best alternative due to constraints.
Matt
41 minutes agoYaeko
6 days agoRuth
11 days agoKrissy
17 days agoLilli
22 days agoAsha
28 days agoDaron
1 month agoShanice
1 month agoDana
2 months agoElin
2 months agoMel
2 months agoNan
3 months agoJamal
3 months agoElouise
2 months agoClay
3 months agoTina
3 months ago