ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsHard
A large enterprise is struggling with managing user identities and their corresponding access rights across hundreds of disparate applications and systems. Employees frequently experience delays in getting necessary access, and auditors find inconsistencies in permissions. Which solution would best address these challenges by centralizing identity management and automating access provisioning and deprovisioning?
- ASingle Sign-On (SSO)
- BIdentity and Access Management (IAM)
- CMulti-Factor Authentication (MFA)
- DDiscretionary Access Control (DAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Identity and Access Management (IAM)
Identity and Access Management (IAM) systems provide a framework for managing digital identities and controlling access to resources across an enterprise. They centralize identity data, automate provisioning/deprovisioning, and streamline access governance, directly addressing the described challenges.
Why the other options are wrong
- A. SSO allows users to log in once for multiple systems but doesn't manage the underlying identities or automate provisioning/deprovisioning.
- C. MFA strengthens authentication but doesn't solve the broader issues of managing identities and access rights across many systems.
- D. DAC is an access model, not a comprehensive system for identity management and automation across disparate systems.
Identity and Access Management (IAM)
A framework of policies, processes, and technologies that manage digital identities and control access to resources and systems within an organization. It encompasses user provisioning, authentication, authorization, and auditing.
- Centralizes identity management across multiple systems.
- Automates the lifecycle of user access (provisioning/deprovisioning).
- Enhances security, compliance, and operational efficiency.
Memory trick: IAM is the master key for all identities and access.