Adequate Security: The level of security considered sufficient to protect an information system, data, or network from unacceptable losses or damage. This typically involves a balance between the potential harm caused by a security incident and the cost and effort of implementing security measures. Adequate security is often defined by regulatory requirements, industry standards, or an organization’s risk tolerance and may vary depending on the nature of the assets being protected and the threat landscape.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D1: Security Concepts and Practices
Related Articles: