课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Accountability

Accountability

- [Narrator] Effective access control systems enforce the principle of accountability. Accountability means that every action taken on a system can be clearly traced back to an individual user without any ambiguity. Administrators can clearly tell who performed an action and the individual can't deny responsibility for that action. There are two prerequisites for ensuring accountability, and they are two of the fundamental requirements for any access control system. The first is identification. Each user of the system must be identified by a unique identifier such as a username. The system and organizational policies must not allow the use of any shared departmental or generic accounts. If two individuals share an account, the system can't distinguish between them and either of the two users can simply blame the other for any action taken under the shared account. Without identification, there is no accountability. The second requirement is authentication. Every account on the system…

内容