166 terms · 75/46/45
Defense № 009 · class: identity / access

Identity & Access Management

Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.

Term

description · examples · notes

Identity and access management encompasses the policies, processes, and technologies for creating, managing, and revoking digital identities and their access rights. The goal is to ensure the right users have the right access to the right resources at the right time.

Description

IAM covers the entire user account lifecycle, from creation at onboarding through role changes to deactivation at offboarding. It includes role assignment, group management, password policies, and directory service integration.

Without adequate IAM, an organization loses track of who has access to what, creating risks of unauthorized access, privilege accumulation, and accounts remaining active after they are no longer needed.

What people often say

  • IAM is just a password reset tool.
  • Once configured, IAM requires no regular maintenance or review.

Covers / does not cover

Covers

  • Centralized user account management and lifecycle
  • Role-based and policy-based access assignment
  • Automated account provisioning and deprovisioning on hire and departure
  • Integration with directory services and applications

Does not cover

  • Monitoring what a user does after login (that is the domain of monitoring and SIEM)
  • Protection against credential theft (complemented by MFA and EDR)
  • Privileged account control at the level requiring PAM

Mentioned in the news

Composite

Threats

reduces 24

Techniques

neutralizes 9