Alternative security measures implemented when a specific compliance requirement cannot be met exactly as defined, but equivalent protection is still achieved. In PCI DSS, compensating controls must provide a comparable level of security, address the same risk, and be properly documented and validated.