ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A healthcare organization is migrating its patient records system to a cloud-based Identity as a Service (IDaaS) provider. The security team is particularly concerned about ensuring the confidentiality and integrity of patient data during authentication and authorization processes handled by the IDaaS. Which control is MOST critical to implement and verify with the IDaaS provider to mitigate these concerns?

  1. ARegular vulnerability scanning of the IDaaS provider's network infrastructure.
  2. BStrong encryption protocols (e.g., TLS 1.3) for all communication channels.
  3. CGeographic redundancy of the IDaaS provider's data centers.
  4. DComprehensive audit logging of all authentication and authorization events.
Show answer & explanation

Correct answer: B. Strong encryption protocols (e.g., TLS 1.3) for all communication channels.

Confidentiality and integrity of data in transit are directly addressed by strong encryption protocols like TLS 1.3. While other options are important for overall security, ensuring secure communication channels is paramount for protecting sensitive patient data during authentication and authorization with an external IDaaS.

Why the other options are wrong

  • A. Vulnerability scanning is important for overall security but doesn't directly address confidentiality/integrity of data *in transit* during authentication.
  • C. Geographic redundancy primarily addresses availability and disaster recovery, not the confidentiality or integrity of data during authentication/authorization.
  • D. Audit logging is vital for accountability and incident response, but it doesn't *prevent* the initial compromise of confidentiality or integrity during transit.

IDaaS Security - Confidentiality & Integrity

Ensuring confidentiality and integrity in IDaaS requires robust controls to protect identity data both at rest and in transit, especially during authentication and authorization.

  • Data in transit: TLS/SSL encryption is critical.
  • Data at rest: Database encryption, access controls.
  • Focus on secure communication between client and IDaaS.

Memory trick: Encrypt All Traffic, Always.

More Identity and Access Management (IAM) questions