ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

An organization is migrating its on-premises applications to a cloud environment. They want a solution that allows employees to use a single set of credentials to access all authorized cloud services and internal applications without re-entering their username and password multiple times. This approach aims to improve user experience and reduce password fatigue. What is the most appropriate access control technology for this requirement?

  1. AMulti-Factor Authentication (MFA)
  2. BSingle Sign-On (SSO)
  3. CIdentity Governance and Administration (IGA)
  4. DPrivileged Access Management (PAM)
Show answer & explanation

Correct answer: B. Single Sign-On (SSO)

Single Sign-On (SSO) is a technology that allows users to authenticate once with a single set of credentials and then gain access to multiple independent software systems without re-entering their credentials. This directly addresses the goal of improving user experience and reducing password fatigue across various applications.

Why the other options are wrong

  • A. MFA enhances authentication security, but doesn't solve the problem of multiple logins across different systems.
  • C. IGA manages the lifecycle of identities and access rights, but SSO is specifically about seamless access across systems after initial authentication.
  • D. PAM focuses on securing and managing highly privileged accounts, not general user access across multiple applications.

Single Sign-On (SSO)

An authentication scheme that allows a user to log in with a single ID and password to gain access to multiple related, yet independent, software systems.

  • Improves user convenience and productivity
  • Reduces password fatigue and support calls
  • Centralizes authentication management

Memory trick: SSO: 'Sign On Once, Smooth Sailing Everywhere!'

More Access Controls Concepts questions