Question
What is Identity and Access Management (IAM), in one sentence that captures both the security and the business side?
Answer
IAM is the set of processes, policies and technologies that controls which subjects may access which protected resources: the right people or machines reach the right assets at the right time for the right reasons, while unauthorised access and fraud are kept out.
* IAM is the gate between subjects who want in and resources that want protection; it decides who gets through and under which conditions. *
The picture to keep in mind is a gate between two things: on one side subjects (people, machines, services), on the other side resources (data, services, even buildings). IAM is everything that decides who gets through that gate and under which conditions.
Gartner's definition is the one worth memorising because it names both halves of the discipline:
- The security half: keep unauthorised access and fraud at bay.
- The business half: help the right people get in at the right time for the right reasons. An IAM system that only blocks is useless; its job is to enable legitimate access, reliably and conveniently.
Notice the three ingredients: processes (registration, onboarding, revocation), policies (who may do what) and technologies (directories, protocols, tokens). Only the last one is "IT". That is why IAM is a management discipline, not just a piece of software.
Go deeper:
Identity management (Wikipedia) — the broad map of the field: what IAM systems do, the standards involved, and the privacy debate around them.
Note saved — thanks!
Question
Which four questions does an IAM system answer about every participant, and what does each question correspond to?
Answer
Who are you? How can you be recognised? What are you allowed to do? How are those limits enforced? They map onto identity, authentication, authorisation and enforcement.
* The four questions in order: identity first, then recognition, then the decision, then its enforcement at runtime. *
The four questions are a compact way to remember the whole field, and they apply equally to persons, machines and services or applications:
| Question | IAM concept | Typical answer |
|---|---|---|
| Who are you? | Identity (registration, identification) | "I am user alice, a student at HSLU." |
| How can you be recognised? | Authentication | Password, token, certificate, biometrics |
| What may you do, what are you authorised for? | Authorisation | Roles, attributes, access rules |
| How are the limits of your authorisation enforced? | Access control at runtime | The application checks the rules on every access |
The order matters: you cannot enforce limits before you know who is asking, and you cannot know who is asking before that person or machine has an identity in the system. Every later topic in IAM is an elaboration of one of these four lines.
Go deeper:
NIST SP 800-63-4 Digital Identity Guidelines — the US reference model; its three volumes map onto identity proofing, authentication and federation.
Note saved — thanks!