From the course: ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Accountability

Accountability

- [Instructor] Effective access control systems, enforced the principle of accountability. Accountability means that every action taken on a system can be clearly traced back to an individual user without any ambiguity. Administrators can clearly tell who performed an action and the individual can't deny responsibility for that action. There are two prerequisites for ensuring accountability, and they are two of the fundamental requirements for any access control system. The first is identification. Each user of the system must be identified by unique identifiers, such as a username. The system and organizational policy must not allow the use of any shared departmental or generic accounts. If two individuals share an account, the system can't distinguish between them, and either of the two users can simply blame the other for any action taken under the shared account. Without identification, there is no…

Contents