The correct answer is Keeping designs as simple and small as possible. Economy of mechanism focuses on keeping security designs as simple and small as possible. Simpler designs are easier to analyze, test, and verify for security vulnerabilities. Complex systems increase the likelihood of security flaws due to interactions between components and difficulty in comprehensive testing. This principle recognizes that complexity is the enemy of security.
Using multiple frameworks for similar functions is incorrect because using multiple frameworks for similar functions increases complexity and goes directly against the principle of economy of mechanism. This approach creates redundancy and potential inconsistencies that can lead to security vulnerabilities.
Adding extra security features beyond requirements is incorrect because adding extra security features beyond requirements increases complexity without clear justification. Each additional feature increases the attack surface and potential for vulnerabilities without necessarily improving security posture.
Implementing redundant security controls is incorrect because while defense in depth is important, implementing redundant controls must be balanced with simplicity. Truly redundant controls (as opposed to layered, complementary controls) can increase complexity and maintenance burden without proportional security benefits.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the principle of economy of mechanism mean in secure design?
Open an interactive chat with Bash
Why is complexity considered the enemy of security?
Open an interactive chat with Bash
What are some common pitfalls of adding extra security features?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Oh snap!
Loading...
Loading...
Loading...
Information Technology Package Join Premium for Full Access