ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium
A financial institution is implementing a new data retention policy that mandates keeping all transaction logs for a minimum of seven years. This policy is primarily driven by regulatory compliance requirements. Which foundational security operations concept is MOST directly addressed by this requirement?
- AAccountability
- BAuditability
- CNon-repudiation
- DHigh Availability
Show answer & explanationAnswer & explanation
Correct answer: B. Auditability
The requirement to retain transaction logs for an extended period, especially for regulatory compliance, directly supports auditability. It ensures that past actions and events can be reconstructed and verified by auditors.
Why the other options are wrong
- A. Accountability ensures individuals are responsible for their actions, which logs contribute to, but the policy's primary driver here is the ability to *prove* or *verify* those actions over time.
- C. Non-repudiation prevents denial of actions, which logs can support, but the long-term retention for regulatory checks points more broadly to auditability.
- D. High Availability ensures systems are operational, which is not the primary purpose of log retention.
Auditability
Auditability refers to the ability to examine and verify the records, processes, and controls of an organization to ensure compliance, integrity, and accountability.
- Relies heavily on comprehensive logging and record keeping.
- Essential for regulatory compliance and internal governance.
- Allows for reconstruction of events and verification of actions.
Memory trick: CIA Triad + AAA + D (Confidentiality, Integrity, Availability, Authentication, Authorization, Accountability, Non-repudiation, Auditability).