ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A financial institution requires that all employees involved in processing customer transactions must have their actions logged and attributable to their individual user account. This ensures that in case of an error or fraudulent activity, the responsible party can be identified. Which access control principle is being emphasized here?

  1. AAuthorization
  2. BLeast Privilege
  3. CSeparation of Duties
  4. DAccountability
Show answer & explanation

Correct answer: D. Accountability

Accountability ensures that users' actions within a system can be traced back to their identity, which is crucial for auditing, non-repudiation, and identifying responsible parties in case of security incidents or errors.

Why the other options are wrong

  • A. Authorization determines what a user can do, not who did what.
  • B. Least Privilege limits access, but doesn't directly address tracing actions back to an individual.
  • C. Separation of Duties prevents a single person from completing a critical task alone, not tracking individual actions.

Accountability (Access Control)

The ability to track and audit user activities within a system, ensuring that actions can be attributed to specific individuals. It supports non-repudiation and aids in forensic investigations.

  • Relies on robust logging and auditing mechanisms.
  • Essential for security forensics and incident response.
  • Often achieved by linking actions to unique user identities.

Memory trick: I AAA: Identify, Authenticate, Authorize, Account for all.

More Access Controls Concepts questions