When dealing with shared, privilaged accounts, especially those for emergencies, what is the BEST way to assure non-repudiation of logs?
Correct Answer: B
The best way to assure non-repudiation of logs when dealing with shared, privileged accounts, especially those for emergencies, is to implement a password vaulting solution. A password vaulting solution is a system that securely stores and manages the passwords for shared or privileged accounts, such as administrator, root, or emergency accounts. A password vaulting solution can provide the following benefits: it can enforce strong password policies, such as complexity, length, and expiration; it can generate random and unique passwords for each account; it can encrypt and protect the passwords from unauthorized access; it can automate the password rotation and synchronization; it can grant or revoke the access to the passwords based on roles, rules, or workflows; it can audit and log the password usage and activities; and it can provide accountability and traceability for the shared or privileged accounts. A password vaulting solution can help to prevent the misuse or compromise of the shared or privileged accounts, and ensure the non-repudiation of logs. References:
CISSP All-in-One Exam Guide, Eighth Edition, Chapter 5: Identity and Access Management, page 248;
[Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 5: Identity and Access Management, page 337]