---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Understanding compensating controls for risk reduction

# Understanding compensating controls for risk reduction {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.  
Note:  
The compensating controls feature is available for host vulnerabilities only.

Applying compensating controls can help in reducing the risk of a vulnerability.

The following table shows the use cases for compensating controls:
{#compensating-controls-overview__table_dbk_wfn_fzb__entry__2}

| Use case | Compensating control |
|-|-|
| A vulnerability in a web server that enables attackers to execute arbitrary code. | Implement a Web application firewall (WAF) to block malicious requests to the web server. |
| A vulnerability in an operating system that enables attackers to escalate privileges to root. | Implement an application control to restrict the execution of applications on the host system. |
| A vulnerability in a database server that enables attackers to access sensitive data. | Implement network segmentation to isolate the database server from other hosts and critical systems. |
[Table 1. Use cases for compensating controls]

{#compensating-controls-overview__table_dbk_wfn_fzb}

For more information on the impact of compensating controls on the risk score of a vulnerable item and remediation task, see [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.").
**Related tasks**   

* [Add a compensating control to the library](https://servicenow-prod.fluidtopics.net/CnRYfdkCzjQjmVMVX77y8A "As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.")
* [Associate compensating controls with CVEs or TPEs for risk reduction requests](https://servicenow-prod.fluidtopics.net/KpW4VxnroVuinqMJhAqS4A "As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace, which can be used for reducing the risk posed by a vulnerability.")
* [Disable or enable risk reduction for a CVE or TPE](https://servicenow-prod.fluidtopics.net/PkBpor8ePECeKOr89863KA "As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.")

