LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What is Identity and Access Management (IAM), in one sentence that captures both the security and the business side?

IAM is the set of processes, policies and technologies that controls which subjects may access which protected resources: the right people or machines reach the right assets at the right time for the right reasons, while unauthorised access and fraud are kept out.

IAM as a gate: subjects (persons, groups, machines) on one side, resources (data, services, buildings) on the other, with processes, policies and technologies deciding who gets through

* IAM is the gate between subjects who want in and resources that want protection; it decides who gets through and under which conditions. *

The picture to keep in mind is a gate between two things: on one side subjects (people, machines, services), on the other side resources (data, services, even buildings). IAM is everything that decides who gets through that gate and under which conditions.

Gartner's definition is the one worth memorising because it names both halves of the discipline:

  • The security half: keep unauthorised access and fraud at bay.
  • The business half: help the right people get in at the right time for the right reasons. An IAM system that only blocks is useless; its job is to enable legitimate access, reliably and conveniently.

Notice the three ingredients: processes (registration, onboarding, revocation), policies (who may do what) and technologies (directories, protocols, tokens). Only the last one is "IT". That is why IAM is a management discipline, not just a piece of software.

Go deeper:

From Quiz: IAM / IAM Fundamentals: Terms, Identity and Actors | Updated: Sep 17, 2026