ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A company is implementing logical access controls for its cloud-based applications. They want to ensure that access rights are automatically adjusted when an employee's job role changes or when they leave the company. This approach aims to reduce the risk of orphaned accounts and unauthorized access. Which of the following IAM components is primarily responsible for managing these lifecycle events?

  1. AAuthentication Services
  2. BIdentity Governance and Administration (IGA)
  3. CDirectory Services
  4. DPrivileged Access Management (PAM)
Show answer & explanation

Correct answer: B. Identity Governance and Administration (IGA)

Identity Governance and Administration (IGA) is a comprehensive set of processes and technologies that manage the entire lifecycle of digital identities and their access rights. This includes provisioning, deprovisioning, access reviews, and ensuring compliance, directly addressing the scenario's need for automatic adjustments based on job role changes or employee departures.

Why the other options are wrong

  • A. Authentication services verify identity, but don't manage the lifecycle of access rights.
  • C. Directory services store identity information but don't automatically adjust access based on lifecycle events.
  • D. PAM focuses on managing and securing highly privileged accounts, not the general lifecycle of all user access.

Identity Governance and Administration (IGA)

A framework that manages the entire lifecycle of digital identities and their access rights, ensuring compliance and reducing risk.

  • Automates provisioning/deprovisioning
  • Includes access reviews and certifications
  • Focuses on policy enforcement and compliance

Memory trick: IAM: 'Identify, Authenticate, Authorize, Govern.'

More Access Controls Concepts questions