Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard
A company is implementing a new security policy that dictates all network devices must have their configurations backed up regularly and stored in an encrypted format. Additionally, all access to these devices for configuration changes must be logged and audited. What overarching security principle is this policy primarily addressing?
- AAccountability
- BLeast Privilege
- CConfidentiality
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: A. Accountability
Accountability ensures that individuals can be held responsible for their actions. By requiring configuration backups (for recovery/evidence), encrypted storage (for integrity/confidentiality of backups), and logging/auditing of ALL access and changes, the policy creates an auditable trail, directly supporting the principle of accountability for network device management.
Why the other options are wrong
- B. Least Privilege restricts user access to only what is necessary, which is a related but distinct principle. The policy focuses on tracking actions, not limiting initial access.
- C. Confidentiality protects information from unauthorized disclosure. While encrypted backups contribute to confidentiality, the emphasis on logging and auditing focuses on who did what, which is accountability.
- D. Defense in Depth involves multiple layers of security. While the policy contributes to overall security, its primary focus on logging and auditing points more specifically to accountability.
Accountability (Security Principle)
The ability to trace all actions on a system to a specific individual or process, ensuring responsibility for those actions.
- Relies heavily on logging and auditing mechanisms.
- Essential for incident response and forensics.
- Supports non-repudiation of actions.
Memory trick: CIA Triad and A for Accountability.