SSCP Systems Security Certified PractitionerAccess ControlsMedium
A new employee is onboarding, and the HR department needs to grant them access to various internal systems. Instead of manually creating accounts and assigning permissions in each system, HR uses a centralized identity management system that automatically provisions the necessary accounts and assigns default roles based on the employee's department and job title. What concept is being demonstrated by this automated process?
- ASingle Sign-On (SSO)
- BIdentity Governance and Administration (IGA)
- CPrivileged Access Management (PAM)
- DFederated Identity Management
Show answer & explanationAnswer & explanation
Correct answer: B. Identity Governance and Administration (IGA)
Identity Governance and Administration (IGA) encompasses the processes and technologies that manage digital identities and access rights across an organization. It includes automating user provisioning, managing roles, enforcing policies, and facilitating compliance, which aligns with the scenario of automatically provisioning accounts and assigning roles.
Why the other options are wrong
- A. SSO allows users to authenticate once and gain access to multiple systems, but doesn't cover the provisioning aspect.
- C. PAM specifically manages and secures privileged accounts, which is a subset of identity management, not the overarching process.
- D. Federated Identity Management enables identity exchange across different security domains, not internal provisioning and role assignment.
Identity Governance and Administration (IGA)
A framework that manages digital identities and access rights throughout their lifecycle, including provisioning, access requests, role management, and compliance.
- Automates identity and access management processes.
- Ensures compliance with security policies and regulations.
- Provides visibility into who has access to what resources.
Memory trick: IGA is the grand conductor of all identity tasks, from hiring to leaving.