4.1 Compensating Controls
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
3 hours 37 minutes
welcome to the cyber E d Mystifying P. C. I. D. S s compliance course.
This module focuses on how to develop strategies to meet PC I compliance objectives.
This video focuses on the implementation of compensating controls to mitigate risks
in instances where the merchant can't meet the requirements do to constraints.
The learning objective is to explore the use of compensating controls in the CD
PC. I recognizes that there may be instances where the merchant is prohibited from meeting. Some of the requirements do too
The constraint maybe do tow business or technical reasons that prevent the implementation of a requirement as explicitly stated in the PC I standard.
So p c. I has put in place some flexibility for the merchant to meet the spirit of the requirement in different ways.
The flexibility is granted with compensating controls.
A compensating control is a work around for a security requirement.
It's another way to reach the objective of a specific security requirement without satisfying the requirement itself.
In other words, it's a plan B to meet a requirement.
Understanding the requirement and its objectives is therefore of the utmost importance in choosing and evaluating a compensating control.
The PC idea says, says that compensating controls will be considered for most requirements but does not specify exactly which requirement and won't consider them for
previously only requirement 3.2, which is the prohibition of storing sensitive authentication data after authorization, was prohibited from having a compensating control apply to it.
But now there's some information floating out there that says even that one could have some compensating controls around them.
So there's more ambiguity.
But as a merchant, you should probably really try to stay away from trying to apply a compensating control to this requirement.
In orderto leverage, a compensating control, the merchant must provide that the roadblock to implementing the requirement is temporary due to a legitimate technical or business constraints.
Temporary is a key word here because work around should never be permanent.
You need to regularly assess to see how the problem can be solved. To meet the mandate from P. C. I.
Every year you're compensating, control will be scrutinized by your assessor, and changing conditions could be a threat to your compliance.
Legitimate is another ambiguous word that is completely left up to interpretation.
You will not win any leniency if you try to use the price of implementation as a legitimate reason.
However, if you're running a mission critical systems on software that's no longer supported, then you are more likely to garner sympathy from your assessor.
You need to be able to demonstrate that your hands are tied at the moment, but they will no longer be in time,
price or lack of expertise. They're not excuses that will allow you to get by.
Compensating control must meet the intent of the requirement it's supposed to replace.
You must have the same or higher level of protective measures and without introducing any other major risks to the environment.
Every compensating control must be supported by a risk analysis and it must be documented.
PC I provides this compensating control worksheet as an appendix to the P. C. I. D. S s guy.
This worksheet will be included in the report submitted by our que Essa.
You need to define what's keeping you from meeting the requirements as stated
what the original objective of the control is,
what risk is associated with your compensating control.
Any explanation of your compensating control,
how the control was validated
and how you're going to maintain the compensating control.
The PC High Council then gives you an example of what it looks like to fill in the worksheet and an acceptable manner.
As a merchant, you have to be aware that most auditors air risk averse.
They understand that if they sign off on the compensating control, another auditor may come in after them. And Dean, you're compensating control. Insufficient.
The audit process may not allow the time for auditor to do a thorough risk assessment of your compensating control to determine its impacts.
So a lot of auditors try to dissuade merchants from using compensating controls.
I say that to say that you must be prepared to thoroughly defend the use of your compensating controls prior to the audit.
And here's just a symbolic picture of the ambiguity around compensating controls between merchants que essays and the P C I s S E.
So I would I would recommend that you stay away from compensating controls unless absolutely necessary, simply because there's very little uniformity around them.
There have been some. Qs is petitioning the PC High Council to publish more examples of acceptable compensating controls to help make it clear for the merchants and the auditors.
So in this video we discussed compensating controls and when to implement them.
We also talked about how to justify your compensating controls to your auditor.
Now for quick wits,
this is a valid reason for compensating control,
lack of funding,
lack of personnel,
lack of vendor support
or lack of organizational support.
If you're running a mission critical application that is no longer supported by the vendor, you can develop compensating controls to address PC I requirements.
True or false?
Compensating control is meant to be a permanent solution to meet a PC. I requirement
this one's false because compensating controls are only meant to be temporary.
Every compensating control must be supported by
a risk analysis
Support of meeting the requirement objective.
We're all of the above
all of the above.
They all must be documented in the compensating control worksheet
Course Assessment - PCI DSS