Accountability
Accountability is the degree to which the actions of an entity — a user, a service, a process — can be traced uniquely back to that entity. It’s a quality attribute, and ISO/IEC 25010 classes it as a sub-characteristic of security.
Systems achieve accountability primarily through logging and audit trails that record who did what and when, combined with strong authentication so that a recorded action can be attributed to a real, verified identity, rather than a shared or spoofed one.
Traceability is the capacity to follow that chain of evidence from an outcome back to its cause.
Accountability is also the basis for non-repudiation. Once an action is accountable and irrefutably attributed, the entity that performed it cannot credibly deny having done so.
References
- ISO/IEC (2023). ISO/IEC 25010:2023 — Systems and software Quality Requirements and Evaluation (SQuaRE) — Quality model.