Generally Accepted System Security Principles

P-16 Simplicity Principle

Copyright(c), 1995 - Management Analytics and Others - All Rights Reserved


Information security professionals should favor small and simple safeguards over large and complex safeguards.


Simple safeguards can be thoroughly understood and tested. Vulnerabilities can be more easily detected. Small, simple safeguards are easier to protect than large, complex ones. It is easier to gain user acceptance of a small, simple safeguard than a large, complex safeguard.