id: "SA-08(28)" title: "Acceptable Security" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.28" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True
Statement
Implement the security design principle of acceptable security in {{ insert: param, sa-08.28_odp }}.
Guidance
The principle of acceptable security requires that the level of privacy and performance that the system provides is consistent with the users’ expectations. The perception of personal privacy may affect user behavior, morale, and effectiveness. Based on the organizational privacy policy and the system design, users should be able to restrict their actions to protect their privacy. When systems fail to provide intuitive interfaces or meet privacy and performance expectations, users may either choose to completely avoid the system or use it in ways that may be inefficient or even insecure.
Assessment Objective
{{ insert: param, sa-08.28_odp }} implement the security design principle of acceptable security.
System and services acquisition policy
system and services acquisition procedures
procedures addressing the security design principle of acceptable security used in the specification, design, development, implementation, and modification of the system
system design documentation
security and privacy requirements and specifications for the system
system security and privacy architecture
personally identifiable information processing policy
privacy notifications provided to users
system security plan
privacy plan
privacy impact assessment
privacy risk assessment documentation
other relevant documents or records
Organizational personnel with information security and privacy responsibilities
organizational personnel with system specification, design, development, implementation, and modification responsibilities
system developers
Organizational processes for applying the security design principle of acceptable security in system specification, design, development, implementation, and modification
mechanisms supporting the application of the security design principle of acceptable security in system specification, design, development, implementation, and modification
mechanisms that enforce security policies