LOGBOOK

HELP

1 / 162
time's up — finish this card
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag
Topic IAM Fundamentals: Terms, Identity and Actors

Question

What is Identity and Access Management (IAM), in one sentence that captures both the security and the business side?

Answer

IAM is the set of processes, policies and technologies that controls which subjects may access which protected resources: the right people or machines reach the right assets at the right time for the right reasons, while unauthorised access and fraud are kept out.

IAM as a gate: subjects (persons, groups, machines) on one side, resources (data, services, buildings) on the other, with processes, policies and technologies deciding who gets through

* IAM is the gate between subjects who want in and resources that want protection; it decides who gets through and under which conditions. *

The picture to keep in mind is a gate between two things: on one side subjects (people, machines, services), on the other side resources (data, services, even buildings). IAM is everything that decides who gets through that gate and under which conditions.

Gartner's definition is the one worth memorising because it names both halves of the discipline:

  • The security half: keep unauthorised access and fraud at bay.
  • The business half: help the right people get in at the right time for the right reasons. An IAM system that only blocks is useless; its job is to enable legitimate access, reliably and conveniently.

Notice the three ingredients: processes (registration, onboarding, revocation), policies (who may do what) and technologies (directories, protocols, tokens). Only the last one is "IT". That is why IAM is a management discipline, not just a piece of software.

Go deeper:

or press any other key
Topic IAM Fundamentals: Terms, Identity and Actors

Question

Which four questions does an IAM system answer about every participant, and what does each question correspond to?

Answer

Who are you? How can you be recognised? What are you allowed to do? How are those limits enforced? They map onto identity, authentication, authorisation and enforcement.

The four IAM questions mapped to identity, authentication, authorisation and access control at runtime

* The four questions in order: identity first, then recognition, then the decision, then its enforcement at runtime. *

The four questions are a compact way to remember the whole field, and they apply equally to persons, machines and services or applications:

Question IAM concept Typical answer
Who are you? Identity (registration, identification) "I am user alice, a student at HSLU."
How can you be recognised? Authentication Password, token, certificate, biometrics
What may you do, what are you authorised for? Authorisation Roles, attributes, access rules
How are the limits of your authorisation enforced? Access control at runtime The application checks the rules on every access

The order matters: you cannot enforce limits before you know who is asking, and you cannot know who is asking before that person or machine has an identity in the system. Every later topic in IAM is an elaboration of one of these four lines.

Go deeper:

or press any other key