Skip to main content
Category: Controlled Unclassified Information

Adequate Security

Simply put

Adequate security means protecting information at a level that matches the risk and the potential harm that could result if the information were lost, misused, or accessed or changed without authorization. It is not about achieving perfect or maximum possible security, but about applying protections that are proportionate to the stakes involved. What counts as adequate can vary depending on the sector and the sensitivity of the information being protected.

Formal definition

Adequate security is generally defined as security commensurate with the risk and the magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. In practice it represents a risk-based, evidence-informed judgment rather than an absolute standard, distinct from both perfect security and the maximum security technically achievable. The specific measures deemed adequate are context-dependent and may differ across government, military, and other sectors; practitioners should verify the applicable interpretation against the current authoritative source governing their system and information type, as this entry does not address implementation, contractual, or agency-specific tailoring requirements.

Why it matters

Adequate security is the organizing principle behind risk-based cybersecurity: it directs organizations to calibrate protections to the risk and the magnitude of harm that would result from the loss, misuse, or unauthorized access to or modification of information. This matters because resources are finite, and treating every system as if it required the maximum security technically achievable is neither practical nor, in most cases, appropriate. The concept reframes the central question from "how much security can we build?" to "how much security does this information and its associated risk warrant?", a judgment that must be made deliberately and defended with evidence.

Because adequacy is a proportional standard rather than an absolute one, it can be misunderstood in two opposite directions. Some readers treat it as a ceiling that justifies minimal effort, while others treat it as an aspiration toward perfect security. Neither is correct: adequate security is generally understood as an evidence-based judgment that sits between perfect security and the maximum security technically possible. A related expert caution is that meeting an adequacy determination is not the same as being secure in an absolute sense, compliance with a standard and actual security posture are distinct, and an adequacy judgment reflects the risk understood at a point in time, which can change.

What counts as adequate is also context-dependent, and this is where practitioners most often go wrong. The level of protection considered adequate can vary across sectors, government, military, and others, and depends on the sensitivity of the information at stake. An adequacy determination appropriate for one sector or information type should not be assumed to transfer to another without verifying the applicable interpretation against the current authoritative source governing the specific system and information involved.

Who it's relevant to

Information System Security Managers and Security Engineers
Those responsible for selecting and applying safeguards use the adequate security concept to justify protections that are commensurate with risk and potential harm rather than defaulting to maximum possible security. They should document the evidence supporting an adequacy judgment and revisit it as risk conditions change.
Authorizing Officials and Risk Decision-Makers
Officials who accept risk on behalf of an organization rely on adequacy as a proportional standard when deciding whether protections match the magnitude of harm at stake. They should treat an adequacy determination as a point-in-time, evidence-based judgment rather than a permanent or absolute guarantee of security.
Compliance Officers and Auditors
Those evaluating whether protections are sufficient should assess adequacy against the risk and potential harm relevant to the specific information and system, recognizing that adequate security is not the same as absolute security and that the applicable interpretation may vary by sector.
Government and Defense Practitioners Across Sectors
Because what counts as adequate can vary across government, military, and other sectors and with the sensitivity of the information, practitioners should verify the applicable interpretation against the current authoritative source governing their system and information type before relying on an adequacy determination made in a different context.

Inside Adequate Security

Risk-Commensurate Protection
Adequate security refers to protective measures that are commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information. The level of protection is not fixed but scales with the sensitivity of the information and the potential impact of a compromise.
Defined Basis in Federal Policy
The term is generally associated with federal acquisition and information security policy, including OMB Circular A-130 and related guidance. Practitioners should verify the exact wording and current definition against the applicable authoritative source, as phrasing may be refined across revisions.
Applicability to Contractor Systems
The concept is frequently invoked in the context of protecting government information residing on or transiting contractor information systems, where the safeguarding obligation attaches to the information rather than solely to who owns the system.
Layered Safeguards
Adequate security is typically achieved through a combination of management, operational, and technical controls, rather than any single measure. The specific control set applied depends on the categorization of the information and the environment in which it resides.

Common questions

Answers to the questions practitioners most commonly ask about Adequate Security.

Does achieving 'adequate security' mean a system is fully secure or free from risk?
No. Adequate security is a risk-based standard, not a guarantee of complete security or the elimination of risk. It generally refers to protections commensurate with the risk and magnitude of harm resulting from loss, misuse, or unauthorized access to or modification of information. Equating adequate security with being 'secure' is a common mistake; the term describes a proportionate, documented level of protection appropriate to the assessed risk, not an absolute state. Continuous monitoring and reassessment remain necessary because the adequacy of controls can change as threats, systems, and information sensitivity evolve.
Is 'adequate security' a fixed checklist of controls that applies the same way to every system?
No. Adequate security is risk-based and context-dependent rather than a single fixed checklist. What constitutes adequate security depends on factors such as the sensitivity of the information, the impact level, the operating environment, and applicable tailoring. Requirements can differ across federal civilian systems under FISMA, DoD systems under the RMF, and systems handling Controlled Unclassified Information (CUI), and state, local, tribal, and territorial obligations may differ as well. Readers should confirm which authority and baseline apply to their specific system rather than assuming a universal control set.
Which authority or publication should I consult to determine what 'adequate security' requires for my system?
The governing source depends on your system's scope. For CUI in nonfederal systems, the term is associated with DFARS clause 252.204-7012 and the safeguarding requirements it references, but you should verify the current clause text and any associated obligations. For federal systems more broadly, the concept aligns with risk-based protections addressed in NIST guidance and FISMA-related requirements. Because the specific applicable standard, baseline, and any tailoring vary by system type and agency, confirm the requirement against the current authoritative source for your environment rather than relying on a single generalized reference.
How do I demonstrate that a system meets 'adequate security'?
Demonstrating adequate security generally involves documenting the risk determination, selecting and implementing controls commensurate with that risk, and maintaining evidence that those controls are in place and operating as intended. This typically includes system security documentation, assessment results, and records supporting ongoing monitoring. Note that assessment and authorization are distinct: showing controls have been assessed is not the same as receiving an authorization decision. Confirm the specific documentation and evidence expectations against the applicable authority for your system.
Is adequate security a one-time determination once controls are implemented?
Generally no. The adequacy of security is expected to be maintained over time rather than established once. Because threats, system configurations, and information sensitivity can change, an ATO is time-bound and subject to continuous monitoring, and controls that were adequate at one point may require reassessment or adjustment. Treat adequate security as an ongoing obligation supported by continuous monitoring rather than a static, one-time milestone.
If a system or service is FedRAMP authorized, does that mean it meets 'adequate security' for DoD purposes?
Not automatically. FedRAMP authorization does not by itself satisfy DoD-specific requirements. DoD systems and systems handling CUI may be subject to additional requirements, impact-level considerations, or contractual obligations beyond a FedRAMP authorization. Assuming FedRAMP authorization equates to adequate security for a DoD context is a common error; confirm the specific requirements applicable to your DoD environment against the current authoritative and contractual sources.

Common misconceptions

Adequate security means a single, universal checklist of controls that applies the same way to every system.
Adequate security is inherently risk-based and scales with the magnitude of harm from a compromise. The appropriate safeguards for a low-impact civilian system generally differ from those for a system handling CUI or a national security system, so implementations vary based on categorization and tailoring.
Meeting the definition of adequate security is equivalent to being fully secure.
Adequate security describes protection commensurate with risk and does not guarantee immunity from compromise. Compliance with a security standard is not the same as being secure; residual risk generally remains and requires ongoing monitoring and management.
Adequate security is a one-time state that, once achieved, remains satisfied.
Because risk and threats evolve, adequate security is best understood as an ongoing obligation. Protections that were commensurate with risk at one point may become insufficient, which is why continuous monitoring and reassessment are generally expected.

Best practices

Categorize the information and system first so that the protective measures you select are demonstrably commensurate with the risk and magnitude of harm from a compromise.
Anchor your interpretation to the current authoritative source (such as the applicable OMB and related federal guidance) and verify the exact definition and any agency-specific tailoring before relying on it.
Apply a layered combination of management, operational, and technical controls rather than depending on a single safeguard to satisfy the adequate security obligation.
Confirm whether the obligation extends to information on contractor systems, and ensure safeguarding requirements follow the information wherever it resides or transits.
Treat adequate security as an ongoing responsibility by establishing continuous monitoring and periodic reassessment as risk, threats, and information sensitivity change.
Document the risk rationale linking your selected controls to the potential harm, so that the adequacy of protection can be defended during assessment and review.