id: "SA-08(22)" title: "Accountability and Traceability" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.22" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True
Statement
Implement the security design principle of accountability and traceability in {{ insert: param, sa-8.22_prm_1 }}.
Guidance
The principle of accountability and traceability states that it is possible to trace security-relevant actions (i.e., subject-object interactions) to the entity on whose behalf the action is being taken. The principle of accountability and traceability requires a trustworthy infrastructure that can record details about actions that affect system security (e.g., an audit subsystem). To record the details about actions, the system is able to uniquely identify the entity on whose behalf the action is being carried out and also record the relevant sequence of actions that are carried out. The accountability policy also requires that audit trail itself be protected from unauthorized access and modification. The principle of least privilege assists in tracing the actions to particular entities, as it increases the granularity of accountability. Associating specific actions with system entities, and ultimately with users, and making the audit trail secure against unauthorized access and modifications provide non-repudiation because once an action is recorded, it is not possible to change the audit trail. Another important function that accountability and traceability serves is in the routine and forensic analysis of events associated with the violation of security policy. Analysis of audit logs may provide additional information that may be helpful in determining the path or component that allowed the violation of the security policy and the actions of individuals associated with the violation of the security policy.
Assessment Objective: {{ insert: param, sa-08.22_odp.01 }} implement the security design principle of accountability;
Assessment Objective: {{ insert: param, sa-08.22_odp.02 }} implement the security design principle of traceability.
System and services acquisition policy
audit and accountability policy
access control policy
procedures addressing least privilege
procedures addressing auditable events
identification and authentication policy
procedures addressing user identification and authentication
procedures addressing the security design principle of accountability and traceability used in the specification, design, development, implementation, and modification of the system
system design documentation
system audit records
system auditable events
system configuration settings and associated documentation
security and privacy requirements and specifications for the system
system security and privacy architecture
system security plan
other relevant documents or records
Organizational personnel with the responsibility for determining system security and privacy requirements
organizational personnel with audit and accountability responsibilities
organizational personnel with system specification, design, development, implementation, and modification responsibilities
system developers
organizational personnel with information security responsibilities
Organizational processes for applying the security design principle of accountability and traceability in system specification, design, development, implementation, and modification
mechanisms supporting the application of the security design principle of accountability and traceability in system specification, design, development, implementation, and modification
mechanisms implementing information system auditing
mechanisms implementing least privilege functions