Compensating security requirement

A compensating security requirement is implemented by an organization in lieu of a recommended security requirement to provide an equivalent or comparable level of protection for the information/control system and the information processed, stored, or transmitted by that system.

More than one compensating requirement may be required to provide the equivalent or comparable protection for a particular security requirement. For example, an organization with significant staff limitations may compensate for the recommended separation of duty security requirement by strengthening the audit, accountability, and personnel security requirements within the information/control system.

Source
Smart Grid Interoperability Panel – Cyber Security Working Group, Smart Grid Cyber Security Strategy and Requirements 5 (Draft NISTIR 7628 Feb. 2010).