week 6

K1.6 The role and types of compensating business control techniques in protecting the digital security of an organisation:

Compensating controls are backup or alternative security measures that are put in place when a primary (main) control fails, is unavailable, or isn’t fully effective.

They act as a safety net to maintain security if the original control:

  • Is temporarily down

  • Can’t be used due to cost, complexity, or compatibility

  • Fails unexpectedly

These controls do not replace the original control, but reduce the risk until the primary control can be restored.


🛡️ Types of Compensating Control Techniques

Compensating controls can be physical or administrative.

Physical Compensating Controls

These are environmental or infrastructure-related measures that support the continuity of systems, especially in the event of failure.

Type Description
Temperature Controls e.g. Air conditioning or cooling systems to maintain safe operating temperatures for IT hardware.
If the main server cooling system fails, backup AC units help prevent overheating and hardware damage.  

 


Administrative Compensating Controls (Policies and Procedures)

These help guide people on how to react or adapt when the usual security controls are not available.

Type Description
Role-Based Awareness Training Training staff to recognise when systems are under risk and how to follow fallback procedures (e.g. manual processes if automation fails).
Standard Operating Procedures (SOPs) Clear instructions for monitoring and reacting to environmental changes, such as power fluctuations or temperature spikes.

 

These policies ensure staff know how to maintain safety and security when the standard systems aren’t working correctly.

 

Backup Security Plan – When the Main Control Fails

Scenario:
A company’s main server cooling system fails, and the temperature begins to rise. You’ve been asked to put together a compensating control plan.
Task:

1. Choose one physical and one administrative compensating control.
2. For each:
          Describe what it is
          Explain how it helps reduce risk
          Identify when it should be used

Extension:
Write a short Standard Operating Procedure (SOP) for what IT staff should do if the environmental controls (like the cooling system) stop working.

 

 


Last Updated
2025-07-11 14:14:53

English and Maths

English


Maths


Stretch and Challenge

Stretch and Challenge


  • Fast to implement
  • Accessible by default
  • No dependencies
Homework

Homework


Equality and Diversity Calendar
How to's

How 2's Coverage




Links to Learning Outcomes

Links to Assessment criteria

 


Files that support this week


| | | | |
Week 5
Prev
Week 6
Prev
Week 7
Prev

Next