CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard
A healthcare organization uses a legacy electronic health record (EHR) system that has known vulnerabilities and is difficult to patch. Replacing the system is cost-prohibitive in the short term. To manage the risk, the organization implements strict network segmentation, restricts access to the system, and performs frequent integrity checks on the data. These actions primarily represent which control strategy?
- ACompensating Controls
- BRisk Avoidance
- CCorrective Controls
- DPreventive Controls
Show answer & explanationAnswer & explanation
Correct answer: A. Compensating Controls
Since the primary control (patching the system or replacing it) is not feasible, the organization is implementing alternative controls (network segmentation, access restriction, integrity checks) to mitigate the risk. These alternative controls that address a weakness when a primary control is not possible are known as compensating controls.
Why the other options are wrong
- B. Risk avoidance would mean not using the EHR system, which is not the case.
- C. Corrective controls fix problems after they occur. While integrity checks can be detective, the overall strategy of segmentation and access restriction is to compensate for an inherent weakness.
- D. While some of these are preventive in nature (e.g., access restriction), the overarching reason for their implementation in this context — to make up for the lack of direct patching/replacement — makes them compensating controls.
Compensating Control
An alternative control that is implemented to mitigate risk when a primary control is not feasible, effective, or available.
- Addresses a control deficiency
- Provides an equivalent level of protection
- Often more complex or costly than primary controls
Memory trick: When the main path is broken, use a COMPENSATING detour!