Question
What counts as "access" in IAM, and what are the typical operations?
Answer
Access is any operation you can perform on a resource; the typical ones are read, write (which includes changing, creating and deleting) and execute.
Access is deliberately defined as an operation, not as "opening a door", because the rules of authorisation are written in terms of operations: a subject may be allowed to read a file but not change it, or to execute a program but not read its source. The classic set is:
- Read
- Write, covering change, create and delete
- Execute
Real systems refine this into finer-grained verbs (approve, share, export, ...), but every such verb is still an operation on a resource, which is what an access rule ("subject may perform operation on resource under condition") refers to.
Note saved — thanks!
Question
What is authentication (Authentifizierung) according to eCH-0219?
Answer
Authentication is the process of verifying a subject's claimed digital identity according to defined requirements set by the targeted assurance level; it checks the validity of one or more authentication means and establishes that the subject controls the secrets used.
The standard's footnote fixes the German usage: a subject authentisiert sich towards a system, a system authentifiziert a subject. It also notes the trend towards passwordless authentication for usability. Synonyms: Authentifikation, Authentisierung.
Go deeper:
Authentication (Wikipedia) — factors, methods and the boundary to authorisation.
Note saved — thanks!