What are Compensating Controls?

The management, operational, and technical controls (i.e., safeguards or countermeasures) employed by an organization in lieu of the recommended controls in the low, moderate, or high baselines, that provide equivalent or comparable protection for an information system.