An end-of-service server cannot be patched, but it still performs as expected for business operations. The team moves the system to a segmented network. Which of the following control types has the team applied?
This is a compensating control because the organization cannot apply the preferred control, which would be patching or replacing the end-of-service server. Instead, it uses network segmentation to reduce exposure and limit the risk. A compensating control is an alternative safeguard used when the primary security requirement cannot be implemented due to technical, operational, or business constraints. Moving the server to a segmented network does not fix the vulnerability itself, so it is not corrective. It may reduce attack paths, but the key issue is that it substitutes for the missing patching capability. A deterrent control discourages unwanted behavior, such as warning signs or legal notices. A preventive control directly blocks incidents, but here the more precise classification is compensating.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit