Chapter 11. Day 11 – Identity and Access Management - Identity Management
This chapter covers provisioning and managing identities, and the access used in the interaction between humans and information systems. The core concepts of identification, authentication, authorization and accountability are covered in detail here. Concepts related to identity as a service or cloud based third-party identity services are covered; and security requirements in such services are covered with illustration.
A candidate for the CISSP exam is expected to have foundational concepts and knowledge in the following key areas of the identity and access management domain:
- Physical and logical access to assets
- Identity management principles and implementation
- Identity as a service
- Third-party identity services
- Access management
- Authorization mechanisms
- The identity and provisioning life cycle
- Preventing or mitigating access control attacks