Accountability and Traceability
LOW MODERATE HIGHRequirements NIST SOURCE
Implement the security design principle of accountability and traceability in [organization-defined systems or system components].
Discussion (NIST Supplemental Guidance)
The principle of accountability and traceability states that it is possible to trace security-relevant actions (i.e., subject-object interactions) to the entity on whose behalf the action is being taken. The principle of accountability and traceability requires a trustworthy infrastructure that can record details about actions that affect system security (e.g., an audit subsystem). To record the details about actions, the system is able to uniquely identify the entity on whose behalf the action is being carried out and also record the relevant sequence of actions that are carried out. The accountability policy also requires that audit trail itself be protected from unauthorized access and modification. The principle of least privilege assists in tracing the actions to particular entities, as it increases the granularity of accountability. Associating specific actions with system entities, and ultimately with users, and making the audit trail secure against unauthorized access and modifications provide non-repudiation because once an action is recorded, it is not possible to change the audit trail. Another important function that accountability and traceability serves is in the routine and forensic analysis of events associated with the violation of security policy. Analysis of audit logs may provide additional information that may be helpful in determining the path or component that allowed the violation of the security policy and the actions of individuals associated with the violation of the security policy.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-8(22) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- systems or system components that implement the security design principle of accountability are defined;
- systems or system components that implement the security design principle of traceability are defined;
- <SA-08(22)_ODP[01] systems or system components> implement the security design principle of accountability;
- <SA-08(22)_ODP[02] systems or system components> implement the security design principle of traceability.
Examine
[SELECT FROM: System and services acquisition policy; audit and accountability policy; access control policy; procedures addressing least privilege; procedures addressing auditable events; identification and authentication policy; procedures addressing user identification and authentication; procedures addressing the security design principle of accountability and traceability used in the specification, design, development, implementation, and modification of the system; system design documentation; system audit records; system auditable events; system configuration settings and associated documentation; security and privacy requirements and specifications for the system; system security and privacy architecture; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with the responsibility for determining system security and privacy requirements; organizational personnel with audit and accountability responsibilities; organizational personnel with system specification, design, development, implementation, and modification responsibilities; system developers; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for applying the security design principle of accountability and traceability in system specification, design, development, implementation, and modification; mechanisms supporting the application of the security design principle of accountability and traceability in system specification, design, development, implementation, and modification; mechanisms implementing information system auditing; mechanisms implementing least privilege functions].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-8(22). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- audit and accountability policy
- access control policy
- identification and authentication policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
- system security and privacy architecture
Testing
- Organizational processes for applying the security design principle of accountability and traceability in system specification, design, development, implementation, and modification
- mechanisms supporting the application of the security design principle of accountability and traceability in system specification, design, development, implementation, and modification
- mechanisms implementing information system auditing
- mechanisms implementing least privilege functions
Other Records
- procedures addressing least privilege
- procedures addressing auditable events
- procedures addressing user identification and authentication
- procedures addressing the security design principle of accountability and traceability used in the specification, design, development, implementation, and modification of the system
- system audit records
- system auditable events
- security and privacy requirements and specifications for the system
- other relevant documents or records