Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A security auditor is reviewing an organization's compliance with data privacy regulations. They need to ensure that the organization can demonstrate exactly who accessed sensitive customer data, when they accessed it, and what actions they performed. Which security and compliance concept is the auditor primarily focused on?
- AAccountability
- BData Sovereignty
- CConfidentiality
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Accountability
Accountability ensures that actions performed on a system can be traced uniquely to an individual or entity, providing a record of 'who did what, when, and where.' This is crucial for auditing and compliance with data privacy regulations.
Why the other options are wrong
- B. Data Sovereignty relates to data being subject to laws of the country where it's stored, not individual action tracing.
- C. Confidentiality protects data from unauthorized disclosure, not tracking actions.
- D. Availability ensures data is accessible, not that actions are traceable.
Accountability (Security)
The security principle that ensures that all actions performed on a system or with data can be uniquely traced back to the individual or entity responsible for those actions, often through logging and auditing mechanisms.
- Answers 'who did what, when, and where'.
- Crucial for compliance, forensics, and incident response.
- Relies on strong authentication and audit trails.
Memory trick: Accountability: Think of it like a security camera always recording 'who did what'.