ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A global company is integrating a new cloud-based Human Resources (HR) application. This application needs to synchronize employee identity data (e.g., new hires, terminations, role changes) with the company's on-premise Active Directory and other SaaS applications in real-time. Which standard is specifically designed to automate and manage user provisioning and deprovisioning across disparate systems?
- ALightweight Directory Access Protocol (LDAP)
- BOpenID Connect (OIDC)
- CSystem for Cross-domain Identity Management (SCIM)
- DSecurity Assertion Markup Language (SAML)
Show answer & explanationAnswer & explanation
Correct answer: C. System for Cross-domain Identity Management (SCIM)
SCIM is an open standard that enables the automation of user provisioning and deprovisioning across different identity management systems, making it ideal for synchronizing identity data between on-premise directories and cloud applications as described.
Why the other options are wrong
- A. LDAP is a protocol for accessing directory services, not a standard for cross-domain automated provisioning of identities.
- B. OIDC is an authentication layer built on OAuth 2.0, primarily for identity verification, not for user provisioning.
- D. SAML is for authentication and authorization (SSO), not for automated user provisioning and deprovisioning.
SCIM (System for Cross-domain Identity Management)
An open standard for automating the exchange of user identity information between identity domains or IT systems.
- Streamlines user provisioning and deprovisioning.
- Reduces manual administration.
- Often used in hybrid and multi-cloud environments.
Memory trick: SCIM Simplifies Cloud Identity Management