CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A retail company's PCI DSS assessment reveals that a legacy point-of-sale server cannot be patched to the latest firmware without breaking compatibility with critical hardware, and the vendor no longer supports updates. To remain compliant, the security team instead isolates the server on a dedicated segmented VLAN, restricts access to two authorized administrators, and enables enhanced logging and alerting on all traffic to and from it. Which type of security control is being implemented?
- ADeterrent control
- BCompensating control
- CPreventive control
- DDetective control
Show answer & explanationAnswer & explanation
Correct answer: B. Compensating control
A compensating control is an alternative safeguard implemented when the originally required control (patching) cannot be applied, providing equivalent risk reduction through other means such as segmentation, restricted access, and enhanced monitoring. This is a common PCI DSS approach for legacy systems.
Why the other options are wrong
- A. Deterrent controls discourage behavior through warnings, which is not the primary function of segmentation and monitoring.
- C. While segmentation has preventive elements, the overall purpose here is to substitute for an unmet requirement, defining it as compensating.
- D. Enhanced logging alone would be detective, but the combined set of measures is meant to replace the missing patch requirement.
Compensating Control
An alternative security measure implemented to satisfy the intent of a required control when the original control cannot be applied, commonly required by PCI DSS for legacy systems.
- Must meet the intent and rigor of the original requirement
- Often used when patching or upgrades are not feasible
- Commonly involves layered measures like segmentation, monitoring, and restricted access
Memory trick: PDCDC: Prevent, Detect, Correct, Deter, Compensate