If you have ever seen one of my presentations on or we have ever discussed technology security or operations, you have likely heard me say something like: At a certain maturity level everything is just exception management. Keep reading to get more details on one of the most common exception management techniques, compensatory or compensating controls.
The ComplianceForge team provides a nice definition:
"Controls are safeguards or countermeasures implemented to manage risks and protect assets. Cybersecurity controls can be technical, administrative, or physical and are designed to reduce vulnerabilities, prevent threats and ensure confidentiality, integrity and availability of information." (ComplianceForge, 2025)
In the simplest of terms your organization has said, "We care about X". The control documents what you are doing to protect "X".