Statutes and regulators require security reasonable to the data's sensitivity, the organization's size, and available measures. Frameworks including NIST and CIS controls supply reference points but are not themselves legal standards.
The standard is deliberately flexible.
Alternative Names:
Reasonable Security|Security Reasonableness
Why it Matters?
Framework alignment supports but does not establish reasonableness, since no framework is legally mandated in most contexts and partial implementation is common, which means the defense rests on documented risk assessment and reasoned prioritization rather than checklist completion. Evidence of known unremediated vulnerabilities is what most damages the position. Documented decisions accepting specific risks with stated rationale defend better than silence.
Frequently Confused with
Related terms
Frequently asked questions
Does framework alignment establish reasonableness?
What most damages the position?





