LOGBOOK

HELP

1 / 162
time's up — finish this card
Other keys: show • Space: good • 1-4: rate • 0: skip • 5: flag
Topic IAM Fundamentals: Terms, Identity and Actors

Question

What counts as "access" in IAM, and what are the typical operations?

Answer

Access is any operation you can perform on a resource; the typical ones are read, write (which includes changing, creating and deleting) and execute.

Access is deliberately defined as an operation, not as "opening a door", because the rules of authorisation are written in terms of operations: a subject may be allowed to read a file but not change it, or to execute a program but not read its source. The classic set is:

  • Read
  • Write, covering change, create and delete
  • Execute

Real systems refine this into finer-grained verbs (approve, share, export, ...), but every such verb is still an operation on a resource, which is what an access rule ("subject may perform operation on resource under condition") refers to.

or press any other key
Topic IAM Glossary (eCH-0219)

Question

What is authentication (Authentifizierung) according to eCH-0219?

Answer

Authentication is the process of verifying a subject's claimed digital identity according to defined requirements set by the targeted assurance level; it checks the validity of one or more authentication means and establishes that the subject controls the secrets used.

The standard's footnote fixes the German usage: a subject authentisiert sich towards a system, a system authentifiziert a subject. It also notes the trend towards passwordless authentication for usability. Synonyms: Authentifikation, Authentisierung.

Go deeper:

or press any other key