A company cannot implement biometric access controls due to budget constraints. Instead, they issue smart cards to employees for authentication. Which type of control does the use of smart cards represent in this scenario?
The use of smart cards as an alternative to biometric access controls is an example of a compensating control. Compensating controls are implemented when a primary control is not feasible, providing a substitute that achieves similar security objectives. In this case, smart cards compensate for the lack of biometric authentication by still providing secure access control. Detective controls aim to identify and respond to incidents, corrective controls are used to limit damage after an incident, and deterrent controls are used to discourage potential attackers; these do not describe a control that substitutes for a primary control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are compensating controls?
Open an interactive chat with Bash
What are the different types of security controls?
Open an interactive chat with Bash
Why might a company prefer smart cards over biometric systems?