What must be true about compensating controls when used?

Study for the PCI Data Security Standard Test. Utilize flashcards and multiple-choice questions, each offering hints and detailed explanations. Prepare thoroughly for your exam and ensure compliance with PCI DSS!

Multiple Choice

What must be true about compensating controls when used?

Explanation:
Compensating controls are alternative measures you put in place when you cannot meet a PCI DSS requirement, and they must be documented in the ROC so there is formal justification, testing, and approval for their use. They must demonstrate they achieve the same security objective as the original control, not simply be added arbitrarily. They are not optional, nor do they replace all other controls; they’re specific accommodations that require evidence and validation within the assessment.

Compensating controls are alternative measures you put in place when you cannot meet a PCI DSS requirement, and they must be documented in the ROC so there is formal justification, testing, and approval for their use. They must demonstrate they achieve the same security objective as the original control, not simply be added arbitrarily. They are not optional, nor do they replace all other controls; they’re specific accommodations that require evidence and validation within the assessment.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy