Definitions[edit | edit source]

Adequate security is

security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, personnel, operational, and technical controls.[1]
protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.[2]
[a] set of minimum security requirements that the system is expected to meet.[3]

References[edit | edit source]

Community content is available under CC-BY-SA unless otherwise noted.