Adequate security
Term · Cybersecurity · MLC-T-CYB-000091
1. Meets minimum tolerable levels of security as determined by analysis, experience, or a combination of both and is as secure as reasonably practicable (i.e., incremental improvement in security would require an intolerable or disproportionate deterioration of meeting other system objectives, such as those for system performance, or would violate system constraints).
2. Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.
3. Security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.
4. Security commensurate with the risk resulting from the loss, misuse, or unauthorized access to or modification of information.
5. security commensurate with the risk and magnitude of the harmresulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, acquisition, development, installation, operational, and technical controls.
6. Security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.
7. Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, personnel, operational, and technical controls.
| Identifier | MLC-T-CYB-000091 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-160v1r1; FIPS 200 from OMB Circular A-130, Appendix III; CNSSI 4009-2015 from OMB Circular A-130; CNSSI 4009-2022 from OMB Circular A-130, Appendix III; NIST SP 800-128 from OMB Circular A-130, Appendix III; NIST SP 800-18 Rev. 1 [Superseded] from OMB Circular A-130, Appendix III; NIST SP 800-53A Rev. 4 [Superseded] from OMB Circular A-130, Appendix III; NIST SP 800-30 Rev. 1 from OMB Circular A-130, Appendix III; NIST SP 800-39 from OMB Circular A-130, Appendix III; NIST SP 800-53 Rev. 4 [Superseded] from OMB Circular A-130, Appendix III (Adapted); NIST SP 800-16; NIST SP 800-128 from OMB Circular A-130; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-137 from OMB Circular A-130, Appendix III; NIST SP 800-37 Rev. 1 [Superseded] from OMB Circular A-130, Appendix III; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000091",
"term": "Adequate security",
"field": "Cybersecurity",
"definition": "1. Meets minimum tolerable levels of security as determined by analysis, experience, or a combination of both and is as secure as reasonably practicable (i.e., incremental improvement in security would require an intolerable or disproportionate deterioration of meeting other system objectives, such as those for system performance, or would violate system constraints).\n\n2. Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.\n\n3. Security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.\n\n4. Security commensurate with the risk resulting from the loss, misuse, or unauthorized access to or modification of information.\n\n5. security commensurate with the risk and magnitude of the harmresulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, acquisition, development, installation, operational, and technical controls.\n\n6. Security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information. This includes ensuring that information hosted on behalf of an agency and information systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability protections through the application of cost-effective security controls.\n\n7. Security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. This includes assuring that systems and applications used by the agency operate effectively and provide appropriate confidentiality, integrity, and availability, through the use of cost-effective management, personnel, operational, and technical controls.",
"references": [
"NIST SP 800-160v1r1",
"FIPS 200 from OMB Circular A-130, Appendix III; CNSSI 4009-2015 from OMB Circular A-130; CNSSI 4009-2022 from OMB Circular A-130, Appendix III; NIST SP 800-128 from OMB Circular A-130, Appendix III; NIST SP 800-18 Rev. 1 [Superseded] from OMB Circular A-130, Appendix III; NIST SP 800-53A Rev. 4 [Superseded] from OMB Circular A-130, Appendix III",
"NIST SP 800-30 Rev. 1 from OMB Circular A-130, Appendix III; NIST SP 800-39 from OMB Circular A-130, Appendix III",
"NIST SP 800-53 Rev. 4 [Superseded] from OMB Circular A-130, Appendix III (Adapted)",
"NIST SP 800-16",
"NIST SP 800-128 from OMB Circular A-130; NIST SP 800-37 Rev. 2 from OMB Circular A-130 (2016); NIST SP 800-53 Rev. 5 from OMB Circular A-130 (2016); NIST SP 800-53A Rev. 5 from OMB Circular A-130 (2016)",
"NIST SP 800-137 from OMB Circular A-130, Appendix III; NIST SP 800-37 Rev. 1 [Superseded] from OMB Circular A-130, Appendix III",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/adequate-security/"
}
Record 91 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.