Compensating controls are appropriate when the preferred remediation cannot currently be implemented but the organization must still reduce exposure. A mission-critical system with an unpatched vulnerability for which no vendor patch exists is a classic example. The system cannot simply be removed from service because the business requires it, and conventional patching is unavailable.
The organization may therefore deploy alternative controls such as network segmentation, restrictive firewall rules, application allowlisting, disabling unnecessary services, enhanced monitoring, IPS signatures, access restrictions, or isolation of affected functionality. These measures do not eliminate the underlying defect; instead, they reduce the probability or impact of exploitation while a permanent solution is developed.
NIST's control framework is designed to allow security controls to be selected and tailored according to organizational mission requirements and risk, supporting the broader principle that organizations may apply appropriate alternative safeguards when operational constraints exist.
Option B requires no compensating control because remediation has already occurred. Option C describes a vulnerability that is not applicable to the organization's systems. Option D represents a false positive and therefore does not constitute an actual exposure requiring mitigation.
Study Guide Reference: Vulnerability Management → Mitigation → Compensating Controls → Patch Availability → Mission-Critical Systems → Segmentation and Monitoring.
Submit