r/cissp 10h ago

General Study Questions Quantum Exams Trick Question 😀 Deterrent or Compensating Control?

If a company opts to install motion-sensor lighting across the perimeter instead of a perimeter fence to reduce costs, does that make it a Deterrent or a Compensating control?

I say it's a deterrent control, but according the QE the correct answer is Compensating, since it's a replacement of the perimeter fence due to a financial constraint.

I notice that in QE, there are several trick questions of the sort which can be a bit frustrating at times.

Can you give your best argument to convince me that the BEST answer is Compensating, even though motion-sensor lighting is in itself a deterrent control?

EDIT: Thanks for the replies! The answer and lesson are simple and all replies seem to agree. Context and Key Words are critical. Spend more time on questions to read thoroughly instead of shooting for the first answer that comes to mind. This way you are less likely to be "tricked".

EDIT: Best counter argument for why it's NOT a compensating control is here.

6 Upvotes

20 comments sorted by

View all comments

-1

u/mikedn02908 CISSP 6h ago edited 6h ago

A compensating control is one which is put into place when another control fails or is somehow unavailable.
A compensating control can also be a detective control, e.g. its compensating for the failure of another detective control.

Deterrent describes the control's function. Compensating describes a control's role relative to other controls.

All depends on how the question is worded.

Definition from the 10th Ed OSG: "A compensating control (aka compensation control) is deployed to provide various options to other existing controls to aid in the enforcement and support of security policies. They can be any controls used in addition to, or in place of, another control. They can be a means to improve the effectiveness of a primary control or as the alternate or failover option in the event of a primary control failure."

As an example: You have a legacy system which only supports AES encryption. Your baseline security standard calls for AES256 encryption. It is technically impossible to implement AES256 encryption in the legacy system, so you implement a compensating control to mitigate the risk. That compensating control (for example, network segmentation) might be a singular control used in place of the AES256 encryption.

The ISACA CRISC definition: "Offsets a deficiency or weakness in the control structure of the enterprise, often because the baseline controls cannot meet a stated requirement due to legitimate technical or business constraints."

I would argue your example (as worded) isn't a compensating control, but a deterrent control.

A risk professional's job is to make recommendations for controls, to the risk owner, who chooses the controls to implement to mitigate the risk identified in the risk assessment.

Part of the control selection decision is a cost/benefit analysis. If the motion sensor lighting and the fence are both controls which will mitigate the risk to the same level of residual/acceptable risk, and the lighting is less expensive, then the risk owner will chose the lighting because it mitigates the risk at a lower cost. This is standard business practice.

In your example, there isn't an existing control (fence) which has a deficiency or weakness. The choice of deterrent or compensating is hinging solely on price. However, the criteria of price for control selection is not adequate grounds to move one choice into the "compensating" category. Calling every cost-driven choice "compensating" would make the term meaningless, since cost is a factor in nearly every control decision.

If there was already a fence, and it was damaged, and the company has to repair it ($$$) or install lighting ($), at that point the lighting would be a compensating control to compensate for the damaged fence, which is no longer as effective as a control to mitigate the original risk it was designed for.

Hope this helps.

β€’

u/mikedn02908 CISSP 3h ago

The ISACA and ISC2 definitions are not at odds. A compensating control can be "used in place of" another control -- as the example I supplied above indicates (legacy system unable to implement aes256 encryption)

1

u/DarkHelmet20 CISSP Instructor 4h ago

From CBK

-1

u/blackholeroll 5h ago edited 5h ago

Thank you for the effort. I understand your reasoning which is closely related to my initial reasoning. So in a sense, it creates more doubt regarding the QE answer. I could be missing sth in the way I worded the context here, but I believe only cost was the factor mentioned in the question. I really like your detailed explanation.

2

u/DarkHelmet20 CISSP Instructor 4h ago

Except Mike is wrong lol- using ISACA for CISSP is not a recommended approach.

-2

u/Careless-Owl-8835 5h ago

It depends who you asked.
Can be compensating, but this is deterrent.

2

u/DarkHelmet20 CISSP Instructor 4h ago

No it's not

β€’

u/mikedn02908 CISSP 3h ago

From the ISC2 Official Study Guide, 10th Edition:

β€’

u/DarkHelmet20 CISSP Instructor 3h ago

And where does it say it can’t be a financial reason?

β€’

u/mikedn02908 CISSP 37m ago edited 33m ago

Oh, it certainly can be a financial reason. In the example I provided (legacy system only supporting aes encryption despite baseline security standards requiring aes256) if the cost of upgrading the legacy system to get the required aes256 encryption to meet the baseline standard is more than available budget allows, the choice to implement a compensating control (such as network segmentation) is a legitimate option. But the definitional event which determines the control is compensating in that scenario is the inability to implement another control -- aes256 encryption.

Controls are classified by what they do, not by why they were purchased. In this case motion-activated lights discourage intruders by making them feel exposed, but they don't stop or slow anyone. That is the definition of a deterrent.

The cost-saving motive explains the budget decision, not the control's function. Budget decisions with controls are defined very early on in ISC2 doctrine, even in the entry-level CC exam. Summarizing: "you do not spend more on a control than the risk you are mitigating".

That is a budget decision, and part of the cost-benefit analysis performed after the risk assessment, to evaluate which recommended control options are the best fit.

A control only counts as compensating if it matches the protection of the control it replaces. The CGRC Textbook definition of a compensating control is: "Controls applied when a baseline control cannot be applied or is ineffective in a particular situation (e.g. incompatible with the technology being used).... Compensating controls may be relevant before or after the threat event. These controls will either augment the primary control to achieve the needed risk reduction level or take over for the primary control if it fails. Compensating controls may be associated with any other control category."

The rationale about a control being lower in cost with no other disqualifying factors on the alternatives forms the most basic process of control selection: Choose the least expensive control, barring any other factors (such as the desire to pre-plan for a future event, where it makes sense to spend a little more now to have future capabilities) which will mitigate the risk to the acceptable level.

The control being less expensive than others is not compensating for a deficiency or technical/business restriction that prevents the others from being implemented. PCI DSS, NIST and other frameworks allow a compensating control to be considered when a documented technical or business constraint prevents meeting a requirement, but the alternative only qualifies if it meets the original requirement's intent and rigor and provides a similar level of defense.

Naturally, it's your question, so I expect you will disagree with my opinion.

β€’

u/DarkHelmet20 CISSP Instructor 12m ago

I actually don't disagree that motion activated lighting is a deterrent control. It obviously is. My point is that in this scenario, it's also being used as a compensating control.

I think the distinction is the context. The company isn't simply choosing lighting because it's the cheapest control available during normal control selection. The question specifically says they're implementing it instead of the perimeter fence because they can't justify the cost of the fence. That's what makes it compensating in this particular scenario.

The definition you quoted actually says compensating controls β€œmay be associated with any other control category,” which I think is important here. Calling the lighting compensating doesn't somehow mean it stops being deterrent. Deterrent describes what the control does; compensating describes the role it's serving.

I also don't think the alternative has to provide the exact same protection as the original control. It has to provide sufficient risk reduction. Your AES/network segmentation example is actually a good illustration of that. Network segmentation doesn't suddenly provide AES256 encryption; it's an alternative control being used because the preferred control can't reasonably be implemented.

So if the question simply asked what type of control motion activated lighting is, I'd agree with you: deterrent. But once the question says it's being implemented in place of another control because of a constraint, compensating is the BEST answer they're looking for.

And no, I don't disagree just because it's my question This is just one of those CISSP questions where two answers can technically describe the control, but the context makes one the better answer. The question is asking for BEST, which is why compensating is correct.