LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What is AAA security, and why is it described as necessary but not sufficient?

Access control by identification, authentication and authorisation (plus accounting) — it answers "who may do what" extremely well and says nothing about anything else.

AAA and the stolen-identity problem

* Both actors reach the same identity check — which is why a stolen identity is indistinguishable from a legitimate user. *

The basic thought is a shift of attention from the network path to the actor. Identification, authentication and authorisation of actors are introduced, with matching protocols and standards; the accounting leg covers charging in the narrow sense and attribution of cause and responsibility in the wider one. Application was at first predominantly to people.

The organisational trajectory is worth remembering: the first implementations were decentralised — every system with its own user list — and the later move was towards centralisation, which is where Identity and Access Management (IAM, IDM, IGM…) grew into a discipline of its own.

The attack followed the same logic as everywhere else: the first protections were simple static passwords, and intruders learned quickly how to steal or forge an identity, or hijack a session. A wrongdoer behind a stolen identity is, to the system, a legitimate user — which is the single most important property of this whole approach. Two reactions:

  • (b1) Improve the procedures — multi-factor authentication, single sign-on, better IAM.
  • (b2) Combine AAA with other security approaches, rather than expecting it to stand alone.

In the model's terms the verdict is precise: it scores very well on the actors clause and leaves good/bad actions and the state of the environment to be covered by other measures. Hence "a necessary but not sufficient approach" — you cannot build modern security without identity, and you cannot build it from identity alone.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026