The Payment Card Industry Data Security Standard (**PCI DSS**) includes one of the most formal [[Security Controls#^comp|compensating control]] processes in use today. It sets out three criteria that must be met for a compensating control to be satisfactory:
- The control must meet the intent and rigor of the original requirement.
- The control must provide a similar level of defence as the original requirement, such that the compensating control sufficiently offsets the risk that the original PCI DSS requirement was designed to defend against.
- The control must be “above and beyond” other PCI DSS requirements.
For example, an organization might find that it needs to run an outdated version of an operating system on a specific machine because software necessary to run the business will only function on that operating system version. Most security policies would prohibit using the outdated operating system because it might be susceptible to security vulnerabilities. The organization could choose to run this system on an isolated network with either very little or no access to other systems as a compensating control.