SSCP Systems Security Certified PractitionerAccess ControlsMedium

A large e-commerce company is implementing a new customer identity management system. They want to allow customers to use their existing social media accounts (e.g., Google, Facebook) to sign up and log in, rather than creating new credentials. Which identity and access management (IAM) concept is being implemented?

  1. APrivileged Access Management (PAM)
  2. BDecentralized Identity Management
  3. CFederated Identity Management
  4. DCentralized Identity Management
Show answer & explanation

Correct answer: C. Federated Identity Management

Federated Identity Management allows users to authenticate with one identity provider (like Google or Facebook) and gain access to resources in other service providers without re-authenticating. This is precisely what the e-commerce company is trying to achieve.

Why the other options are wrong

  • A. PAM focuses on managing and securing accounts with elevated permissions within an organization, not on customer authentication via external identity providers.
  • B. Decentralized Identity Management often refers to self-sovereign identity, where users control their own identities, which is different from using existing social media accounts as identity providers.
  • D. Centralized Identity Management typically refers to a single, authoritative source for identities within one organization, not across different organizations.

Federated Identity Management

A system that allows for the portability of identity information across multiple, independent domains, enabling users to authenticate once and access various services without re-authentication.

  • Uses trusted identity providers (IdPs).
  • Enhances user convenience (single sign-on).
  • Reduces administrative burden for service providers.

Memory trick: Federated Friends help you log in everywhere.

More Access Controls questions