Compensating controls Sample Clauses
Compensating controls. A technical, operational, or management cyber security control employed by an organization in lieu of a required or recommended cyber security control that provides an equivalent or better level of protection for a critical asset.
Compensating controls. Receiving Reports may be prepared by staff in a unit separate from 'the Receiving/Storage, Distribution, and Control units, preferably' an Inspection or Quality Control Unit. In this way, Receiving/Storage staffs are responsible only for updating the perpetual inventory records that must be reconciled to Receiving Reports they do not control. In the absence of a separate Inspection unit, the Purchase Order when accompanied by the vendor's Delivery Receipt signed by staff of the Receiving/Storage area serves as a source document for receipt of stock. Management is notified when the delivery does not match the Purchase Order before goods are moved into storage. The, Purchase Order, prepared by staff apart from those in Receiving/Storage,' and supported by the Delivery Receipt, becomes the critical document for recording inventory accurately. The perpetual inventory records may be maintained by staff of the Control unit. In this instance, Receiving/Storage staff prepares the Receiving Report, but does not maintain the perpetual inventory records. In all Instances given below, where staff from a separate unit is not available and two documents that are in agreement are required, these same documents are used to update the perpetual inventory records, Attachment A
Compensating controls. Receiving Reports may be prepared by staff from a unit separate from the Receiving/Distribution, storage, and Control units, preferably an Inspection or Quality Control Unit. Release documentation may be prepared by staff from a unit separate from the Receiving/Distribution, storage, and Control units. In the absence of a separate unit, a properly authorized Requisition Order when fully supported by a Receiving Receipt signed by an authorized end-user serves as a source document for release of stock.
