Name:individual accountability for all assets and actions
Each information asset is identified as to ownership and
stewardship and the owner and steward are held accountable for those
assets. Examples include document tracking, owner-based access control
decisions, and mandatory actions taken in cases where individuals fail
to carry out their responsibility.
Complexity: This is not complex to do, but may require substantial overhead.