Domain 5 · 13% of the exam
Identity and Access Management (IAM)
Security professionals must understand the principles of identity and access management and the different tools and techniques that can be used to manage user accounts and control access to information and systems. This includes understanding user authentication and authorization mechanisms, managing privileged accounts, and implementing SSO and FIM. Additionally, access control monitoring and logging are critical for detecting and preventing unauthorized access and providing an audit trail for forensic analysis.
Learning objectives
- Explain the identity lifecycle as it applies to human and nonhuman users.
- Compare and contrast access control models, mechanisms and concepts.
- Explain the role of authentication, authorization and accounting in achieving information security goals and objectives.
- Explain how IAM implementations must protect physical and logical assets.
- Describe the role of credentials and the identity store in IAM systems.
Key topics
- Control Access
- Design Strategy
- Implementation
- Identity & Account Management
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01FacilitiesLarge enterprises demonstrate the need to have a coordinated, cohesive approach for the overall administration and operation of their physical access control systems.7 slides · 2 min read
- 02Account Access ReviewAccount access reviews periodically evaluate user permissions, ensuring access remains appropriate, compliant, and aligned with organizational roles and policies.5 slides · 3 min read
- 03Access Control (AC) ModelsRole-Based Access Control (RBAC)12 slides · 5 min read
- 04Credential Management SystemsA credential is the binding between an authenticator and an identifier (user/service/ system). A credential management system (CMS) is an established form of issuing and managing credentials, based on software.9 slides · 2 min read
- 05Privilege EscalationPrivilege escalation is the act of elevating access permissions to protected resources by exploiting a bug, design flaw or configuration oversight in an operating system or software application.5 slides · 2 min read
- 06Job or Duties ReviewRegularly reviewing user permissions in response to changes in job roles or responsibilities helps maintain appropriate access and prevents privilege creep.3 slides · 1 min read
- 07Registration, Proofing, and Establishment of IdentityThe Digital Identity Guidelines of NIST SP 800-63-3 contain recommendations to support, among other items, requirement for identity proofing and registration.4 slides · 1 min read
- 08ApplicationsOrganizations use applications to perform tasks and must manage user access and data to ensure security and compliance.2 slides · 1 min read
- 09OpenID and Authentication and OpenID ConnectTwo more modern protocols are commonly used together to provide authentication services.4 slides · 2 min read
- 10Single Sign-On (SSO)Single Sign-On (SSO) defines a unified logon experience, from the viewpoint of the end user, when accessing one or more systems.5 slides · 2 min read
- 11Federated Identity with a Third-Party ServiceFederated identity enables users to access multiple systems with third-party credentials, streamlining authentication and improving security across organizations.3 slides · 1 min read
- 12Access Control as a SystemAccess control systems enforce who can view or use resources, combining policies, technologies, and oversight to safeguard data and operations.6 slides · 2 min read
- 13Access Control as a System, Logical Access Control Systems, and Physical Access Control Systems (PACS)Access Control as a System, Logical Access Control Systems, and Physical Access Control Systems (PACS)12 slides · 6 min read
- 14Physical Access Control SystemsA physical access control system restricts who or what can enter a secured area, using defined rules and standards to enforce authorization.2 slides · 1 min read
- 15Case Study - U.S. Department of Homeland SecurityCase studyLarge enterprises demonstrate the need for a coordinated, cohesive approach in the overall administration and operation of their physical access control (AC) systems.5 slides · 2 min read
- 16Possible Responses (Case Study - U.S. Department of Homeland Security)Case study answersPossible Responses (Case Study: U.S. Department of Homeland Security)1 slides · 2 min read
- 17Role-Based Access ControlRole-Based Access Control is a security framework that organizes system access around job functions, aligning permissions with responsibilities rather than individual users.7 slides · 4 min read
- 18Logical Access Control SystemsLogical access control systems manage user permissions within operating systems, applications, and networks, often combining built-in features and add-on security solutions.5 slides · 2 min read
- 19Single versus Multifactor Authentication (MFA)Single-factor authentication relies on one credential, while multifactor authentication combines methods to significantly strengthen identity verification and reduce compromise risk.4 slides · 2 min read
- 20Just-in-Time IdentityJust-in-time identity grants users with temporary, time-limited access to resources, reducing security risks by providing permissions only when needed and for a defined period.8 slides · 5 min read
- 21Identity and Access Management (IAM) ImplementationImplementing identity and access management ensures secure, role-based access to systems and data, improving security, compliance, and operational efficiency across an organization.4 slides · 1 min read
- 22ProvisioningUsers may request they be granted access to systems resources, and that it provides certain permissions.4 slides · 2 min read
- 23Case Study - DropboxCase studyThe Dropbox data breach of 2012 was a significant incident that exposed vulnerabilities in the popular cloud storage service, affecting millions of users.4 slides · 1 min read
- 24Possible Responses (Case Study - Dropbox)Case study answers1. What measures could an organization implement to control physical access to its data center and ensure only authorized personnel can enter?1 slides · 1 min read
- 25Disable and DeprovisionAll user identities come to an end. Human users may leave the organization, or so change their association with it that their systems identity should not be left active. (Death, of course, may lead to their systems identity being disabled and then…2 slides · 1 min read
- 26IAM Administration ChoicesIdentity and access management administration can follow centralized, decentralized, or hybrid approaches, balancing control, flexibility, and scalability based on organizational size, structure, and security needs.7 slides · 4 min read
