logo

Reasonable Cybersecurity: From Legal Theory to Practice

ID: e779764d-6b21-5288-b862-e2951146ca7e

STIX ID: report--e779764d-6b21-5288-b862-e2951146ca7e

Feed Name: CISecurity.org Insights Blog

Date Published: 2025-09-24

Date Updated: 2026-04-19

...
...

This CIS article explains the growing legal and regulatory emphasis on “reasonable cybersecurity,” advocating for risk-based, defensible security programs aligned to frameworks like the CIS Controls and CIS RAM. It highlights state laws referencing recognized standards, introduces Implementation Groups to tailor safeguards by organizational context, and promotes the CIS Guide to Defining Reasonable Cybersecurity to help leaders document and justify appropriate controls. The focus is on practical, auditable security decisions that protect both organizations and consumers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.