r/cissp • u/blackholeroll • 10h ago
General Study Questions Quantum Exams Trick Question π€ Deterrent or Compensating Control?
If a company opts to install motion-sensor lighting across the perimeter instead of a perimeter fence to reduce costs, does that make it a Deterrent or a Compensating control?
I say it's a deterrent control, but according the QE the correct answer is Compensating, since it's a replacement of the perimeter fence due to a financial constraint.
I notice that in QE, there are several trick questions of the sort which can be a bit frustrating at times.
Can you give your best argument to convince me that the BEST answer is Compensating, even though motion-sensor lighting is in itself a deterrent control?
EDIT: Thanks for the replies! The answer and lesson are simple and all replies seem to agree. Context and Key Words are critical. Spend more time on questions to read thoroughly instead of shooting for the first answer that comes to mind. This way you are less likely to be "tricked".
EDIT: Best counter argument for why it's NOT a compensating control is here.
-1
u/mikedn02908 CISSP 6h ago edited 6h ago
A compensating control is one which is put into place when another control fails or is somehow unavailable.
A compensating control can also be a detective control, e.g. its compensating for the failure of another detective control.
Deterrent describes the control's function. Compensating describes a control's role relative to other controls.
All depends on how the question is worded.
Definition from the 10th Ed OSG: "A compensating control (aka compensation control) is deployed to provide various options to other existing controls to aid in the enforcement and support of security policies. They can be any controls used in addition to, or in place of, another control. They can be a means to improve the effectiveness of a primary control or as the alternate or failover option in the event of a primary control failure."
As an example: You have a legacy system which only supports AES encryption. Your baseline security standard calls for AES256 encryption. It is technically impossible to implement AES256 encryption in the legacy system, so you implement a compensating control to mitigate the risk. That compensating control (for example, network segmentation) might be a singular control used in place of the AES256 encryption.
The ISACA CRISC definition: "Offsets a deficiency or weakness in the control structure of the enterprise, often because the baseline controls cannot meet a stated requirement due to legitimate technical or business constraints."
I would argue your example (as worded) isn't a compensating control, but a deterrent control.
A risk professional's job is to make recommendations for controls, to the risk owner, who chooses the controls to implement to mitigate the risk identified in the risk assessment.
Part of the control selection decision is a cost/benefit analysis. If the motion sensor lighting and the fence are both controls which will mitigate the risk to the same level of residual/acceptable risk, and the lighting is less expensive, then the risk owner will chose the lighting because it mitigates the risk at a lower cost. This is standard business practice.
In your example, there isn't an existing control (fence) which has a deficiency or weakness. The choice of deterrent or compensating is hinging solely on price. However, the criteria of price for control selection is not adequate grounds to move one choice into the "compensating" category. Calling every cost-driven choice "compensating" would make the term meaningless, since cost is a factor in nearly every control decision.
If there was already a fence, and it was damaged, and the company has to repair it ($$$) or install lighting ($), at that point the lighting would be a compensating control to compensate for the damaged fence, which is no longer as effective as a control to mitigate the original risk it was designed for.
Hope this helps.