Compensating Controls
A process used to mitigate risk when not able to meet a PCI DSS requirement.
A process used to mitigate risk when not able to meet a PCI DSS requirement.
Compensating controls may be considered when an entity cannot meet a requirement exactly as stated, due to either legitimate technical or documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other controls. Compensating controls must:
Many organizations that fail to meet all requirements of PCI DSS are adopting the use of compensating controls, but this may not be an easy task, as it requires a lot of effort and turns out to be costly in the long run. These controls may also not be acceptable as a route to PCI DSS compliance in future. To learn more visit http://pcidsscompliance.net/overview/what-are-compensating-controls/
Read more about compliance