The IT Law Wiki

Adequate security

32,068pages on
this wiki
Add New Page
Add New Page Talk0

Definitions Edit

Adequate security is

security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, personnel, operational, and technical controls.[1]
[A] set of minimum security requirements that the system is expected to meet.[2]

{{Quote|protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.[3]

References Edit

  1. OMB Circular No. A-130, App. III, (A)(2)(a); NIST Special Publication 800-53; FIPS 200.
  2. Principles for Cybersecurity and Critical Infrastructure Protection, at 113.
  3. DFARS Clause 252.204-7012(a).

Also on Fandom

Random Wiki