Accountability
The ability to trace each action on a system to the one individual who performed it, which depends on unique accounts, strong authentication and protected audit records.
In identity and access management, accountability means that actions can be traced back to the specific person or process that performed them. Study sources commonly present it as the end of a chain: identification states who a subject claims to be, authentication proves the claim, authorisation limits what the subject may do, and accounting records what it did. The ISC2 exam outline names the last three as AAA; identification is commonly added at the front and accountability named as the result.
Accountability needs every link to hold. If several people share one account, the log shows what the account did but not which person did it, so a shared credential weakens accountability however detailed the logging is. The same applies when authentication is weak or the audit trail can be edited. Accountability is narrower than non-repudiation, which aims to produce evidence strong enough that the actor cannot credibly deny the action to a third party. In governance the word also means being answerable for an outcome, a different sense from the traceability meant here.
Exam relevance: a scenario is likely to describe shared or generic accounts and ask what is lost. Candidates are expected to identify accountability, and to recognise that unique identities and protected audit records are the usual remedy rather than more logging on its own.