Under active development Content is continuously updated and improved · Last updated Feb 18, 2026, 2:55 AM UTC

500.12(b)500.12(b)

>Control Description

If the covered entity has a CISO, the CISO may approve in writing the use of reasonably equivalent or more secure compensating controls. Such controls shall be reviewed periodically, but at a minimum annually.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.