ZenGRC

Compensating Controls: What You Need to Know

Compensating controls in PCI DSS compliance are alternative security measures implemented when an organization cannot meet a specific requirement due to legitimate technical or business constraints, provided these controls sufficiently mitigate the associated risks, meet the intent and rigor of the original requirement, and often offer equal or greater protection than the prescribed method, serving as temporary solutions rather than cost-saving shortcuts.

PCI DSS compliance includes over 100 pages of requirements, but the Appendices provide guidance on limiting risks and scope. Compensating controls allow organizations to comply with PCI DSS requirements when their current architecture doesn't support a specific requirement.

What Is the Definition of Compensating Controls?

According to Appendix B of the PCI FAQ document:

Compensating controls may be considered for most PCI DSS requirements when an entity cannot meet a requirement explicitly as stated, due to legitimate technical or documented business constraints, but has sufficiently mitigated the risk associated with the requirement through implementation of other, or compensating, controls.

Each PCI DSS requirement must be met, but sometimes the prescribed method is burdensome. The standard aims for consistency in information protection, but if you can protect information in a way that meets the intent of the PCI DSS requirement and is more secure than the prescribed method, you may use a compensating control. However, compensating controls are not intended to be cheaper alternatives; they are meant to provide an alternative that meets the fundamental purpose of the standard, often holding organizations to a higher standard of care.

How to Meet the Intent and Rigor of the Original PCI DSS Requirement

Compensating controls are meant to address gaps in compliance and are not intended as permanent solutions. For example, PCI DSS Requirement 1 is to "Install and maintain a firewall configuration to protect cardholder data." If you lack a firewall, you must implement a system of controls that meets the intent and rigor of the requirement until a firewall is in place. The compensating control must protect information as well as, or better than, a firewall would.

Providing a Similar Level of Defense

A compensating control must sufficiently offset the risk that the original PCI DSS requirement was designed to defend against. For example, if a cabin in the woods has no door and there are bears, moving a heavy dresser in front of the doorway might suffice, but a curtain would not. The compensating control must reduce risk to at least the same level as the original control.

Being “Above and Beyond” Other PCI DSS Requirements

PCI DSS does not allow existing requirements to be used as compensating controls for the same item under review. For example, password complexity requirements cannot compensate for the lack of encrypted password transmission, as they do not address the risk of interception and are already required.

However, existing requirements may be used as compensating controls if they are required for another area but not for the item under review. For example, two-factor authentication (2FA) is required for remote access, but using 2FA within the internal network can be a compensating control for non-console administrative access if it addresses the risk and is properly implemented.

Additionally, existing requirements can be combined with new controls to form a compensating control. For instance, if encryption cannot be used to render cardholder data unreadable, a combination of internal network segmentation, IP/MAC address filtering, and 2FA may serve as a compensating control if it addresses all aspects of the original requirement.

Being Commensurate with the Additional Risk

Compliance is risk-based. When developing a compensating control, assess the risk of the original asset and compare it to the risk of your control. If your compensating control introduces greater risk than the prescribed PCI control, it is not sufficient. Compensating controls must go "above and beyond" the PCI requirement to be acceptable.

The PCI DSS aims to standardize industry practices for protecting cardholder data. The definition of compensating controls is intentionally strict to encourage organizations to follow prescribed controls and maintain consistency and security across the industry.