Compensating Controls definition

Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief Information Security Officer or his or her designee to be impractical to implement at the present time due to legitimate technical or business constraints. Such alternative mechanisms must: (1) meet the intent and rigor of the original stated requirement; (2) provide a similar level of security as the original stated requirement; (3) be up-to-date with current industry accepted security protocols; and (4) be commensurate with the additional risk imposed by not adhering to the original stated requirement. The determination to implement such alternative mechanisms must be accompanied by written documentation demonstrating that a risk analysis was performed indicating the gap between the original security measure and the proposed alternative measure, that the risk was determined to be acceptable, and that the Chief Information Security Officer or his or her designee agrees with both the risk analysis and the determination that the risk is acceptable.
Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief Information Security Officer or his or her designee to be impractical to implement at the present time due to
Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief Information Security Officer or his or her designee to be impractical or unreasonable to implement at the applicable time due to legitimate technical or business constraints. Such alternative mechanisms must: (a) meet the intent and rigor of the original stated requirement; (b) provide a similar level of security as the original stated requirement; (c) be materially and substantively up-to-date with current industry accepted security protocols; and (d) be commensurate with the additional risk imposed by not adhering to the original stated requirement. The determination to implement such alternative mechanisms must be accompanied by written documentation demonstrating that a risk analysis was performed indicating the gap between the original security measure and the proposed alternative measure, that the risk was determined to be acceptable, and that the Chief Information Security Officer or his or her designee agrees with both the risk analysis and the determination that the risk is acceptable. Compensating Controls shall not be utilized as permanent alternative security measures and shall be reevaluated for security effectiveness at least every ninety (90) days to determine whether to retain the Compensating Control as the appropriate security measure or to implement an alternative as the permanent security measure. Written security effectiveness documentation shall be prepared and reviewed by the Chief Information Security Officer or his or her designee and shall be kept for a period of one (1) year following the termination of usage of any such alternative mechanism.

Examples of Compensating Controls in a sentence

  • Method(s) used: ☐ Pseudonymized ☐ Anonymized ☐ De-Identified ☐ Masked/Scrambled ☐ Other Compensating Controls: [Insert identified controls: _ ] ☐ None Notices If Avanade will collect Client Personal Data from Data Subjects on Client’s behalf as part of the Services, Avanade will, as directed by Client, use a privacy notice and/or consent request mechanism provided or expressly approved by Client.


More Definitions of Compensating Controls

Compensating Controls means mechanisms put in place to satisfy a security requirement that are not explicitly as stated, due to legitimate technical or documented business constraints, but still sufficiently mitigate the risk associated with the requirement. TERM DEFINITION Compliance means evidence of having met a specific set of policies, standards, laws, frameworks regulations, etc. Concurrent sessions means when there is more than one user accessing the same computer resource at the same time or in the same predefined period of time Configuration means any arrangements to code, updates, patches and processes to an Information Resource.
Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief Information Security Officer or his or her designee(s) to be impractical to implement at the present time due to legitimate technical or business constraints. Such alternative mechanisms must: (1) meet the intent of the original stated requirement; (2) provide a similar level of security as the
Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief Information Security Officer or his or her designee to be impractical to implement at the present time due to legitimate technical or business constraints. Compensating Controls must be suitable to protect the system and consistent with current industry accepted security protocols. The determination to implement Compensating Controls must be accompanied by written documentation demonstrating that a risk analysis was performed indicating the gap between the original security measure and the proposed alternative measure, that the Compensating Control was determined to be acceptable in light of such risk, and that the Chief Information Security Officer agrees
Compensating Controls means actions or processes that yield a similar output to standard operating procedures, but that are temporary in nature.
Compensating Controls means alternative mechanisms that are put in place to satisfy the requirement for a security measure that is determined by the Chief
Compensating Controls means the definition in PCI DSS Appendix B of “Compensating Controls.”

Related to Compensating Controls

  • External Account is your account at another financial institution (i) to which you are transferring funds from your Eligible Transaction Account; or (ii) from which you are transferring funds to your Eligible Transaction Account.

  • Voting Control means, with respect to a share of Class B Common Stock, the power (whether exclusive or shared) to vote or direct the voting of such share by proxy, voting agreement or otherwise.

  • Export Controls Software available on the Services is further subject to United States Export Controls. No software available on the Services may be downloaded or exported (i) into (or to a national or resident of) any country to which the United States has embargoed goods; or (ii) to anyone on the United States Treasury Department's list of Specially Designated Nationals or using the Commerce Department's Table of Deny Orders. By downloading any Software, you represent and warrant that you are not located in, or under the control of, or a national or resident of any such country or on any such list.

  • tender for income-generating contracts means a written offer in the form determined by an organ of state in response to an invitation for the origination of income-generating contracts through any method envisaged in legislation that will result in a legal agreement between the organ of state and a third party that produces revenue for the organ of state, and includes, but is not limited to, leasing and disposal of assets and concession contracts, excluding direct sales and disposal of assets through public auctions; and

  • Institutional Controls or “ICs” shall mean Proprietary Controls and state or local laws, regulations, ordinances, zoning restrictions, or other governmental controls or notices that: (a) limit land, water, or other resource use to minimize the potential for human exposure to Waste Material at or in connection with the Site; (b) limit land, water, or other resource use to implement, ensure non-interference with, or ensure the protectiveness of the RA; and/or (c) provide information intended to modify or guide human behavior at or in connection with the Site.

  • Internal Procedures means in respect of the making of any one or more entries to, changes in or deletions of any one or more entries in the register at any time (including without limitation, original issuance or registration of transfer of ownership) the minimum number of the Warrant Agent’s internal procedures customary at such time for the entry, change or deletion made to be complete under the operating procedures followed at the time by the Warrant Agent, it being understood that neither preparation and issuance shall constitute part of such procedures for any purpose of this definition;