Where technical or business reasons restrict the ability to remediate an identified vulnerability, no mitigating or compensating controls are investigated and applied
Context and Guidance: Assets (such as networks, systems, and applications) can have cyber vulnerabilities. Some vulnerabilities are already known, and can be patched. Other vulnerabilities are yet to be discovered, highlighting the importance of preventative and compensating controls.
Applying a security patch is a common method to remediate a cybersecurity vulnerability, however it is not the only method. If applying a security patch is infeasible, you should explore and implement alternate controls.
No cross-framework mappings available