id: "SA-08(28)" title: "Acceptable Security" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.28" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True


Statement

Implement the security design principle of acceptable security in {{ insert: param, sa-08.28_odp }}.

Guidance

The principle of acceptable security requires that the level of privacy and performance that the system provides is consistent with the users’ expectations. The perception of personal privacy may affect user behavior, morale, and effectiveness. Based on the organizational privacy policy and the system design, users should be able to restrict their actions to protect their privacy. When systems fail to provide intuitive interfaces or meet privacy and performance expectations, users may either choose to completely avoid the system or use it in ways that may be inefficient or even insecure.

Assessment Objective

{{ insert: param, sa-08.28_odp }} implement the security design principle of acceptable security.

System and services acquisition policy

system and services acquisition procedures

procedures addressing the security design principle of acceptable security used in the specification, design, development, implementation, and modification of the system

system design documentation

security and privacy requirements and specifications for the system

system security and privacy architecture

personally identifiable information processing policy

privacy notifications provided to users

system security plan

privacy plan

privacy impact assessment

privacy risk assessment documentation

other relevant documents or records

Organizational personnel with information security and privacy responsibilities

organizational personnel with system specification, design, development, implementation, and modification responsibilities

system developers

Organizational processes for applying the security design principle of acceptable security in system specification, design, development, implementation, and modification

mechanisms supporting the application of the security design principle of acceptable security in system specification, design, development, implementation, and modification

mechanisms that enforce security policies