Compensating Controls
Compensating controls are controls that replace impractical or unfeasible key controls.
- likely need to explain to auditors how it will fulfill the intent and purpose of the control you’re replacing
- E.g., Using Linux OS when some systems don’t have enough processing power to run antivirus software because Linux is less susceptible to malware