Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A regulatory body requires that an organization must be able to demonstrate that its data processing activities comply with data privacy laws and that all access to sensitive information is logged for retrospective analysis. Which security concept is primarily being addressed by this requirement?

  1. AAvailability
  2. BConfidentiality
  3. CIntegrity
  4. DAccountability
Show answer & explanation

Correct answer: D. Accountability

Accountability ensures that actions performed on a system can be traced back to an individual or entity. The requirement to 'demonstrate compliance' and have 'all access to sensitive information logged for retrospective analysis' directly supports accountability, as it allows for tracking who did what, when, and where, which is crucial for proving adherence to regulations.

Why the other options are wrong

  • A. Availability ensures systems and data are accessible when needed.
  • B. Confidentiality focuses on preventing unauthorized disclosure of information.
  • C. Integrity ensures data accuracy and prevents unauthorized modification.

Accountability (Security)

The ability to trace all actions performed on a system or with data back to a specific individual or entity, ensuring responsibility for those actions.

  • Achieved through logging, auditing, and unique user identifiers.
  • Essential for incident response, compliance, and legal proceedings.
  • Supports non-repudiation by linking actions to actors.

Memory trick: Accountability is like a detailed journal, showing exactly who wrote what and when.

More Describe the concepts of security, compliance, and identity questions