ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard
A security engineer is configuring a new system where user provisioning needs to be highly automated and synchronized across multiple disparate systems (e.g., HR system, Active Directory, cloud applications). The goal is to ensure that when a new employee is hired, their accounts are created automatically, and when they leave, their access is revoked consistently across all systems. Which protocol or standard is MOST suitable for automating identity provisioning and de-provisioning in this complex environment?
- ALightweight Directory Access Protocol (LDAP)
- BOpenID Connect (OIDC)
- CSystem for Cross-domain Identity Management (SCIM)
- DSecurity Assertion Markup Language (SAML)
Show answer & explanationAnswer & explanation
Correct answer: C. System for Cross-domain Identity Management (SCIM)
SCIM (System for Cross-domain Identity Management) is specifically designed to automate the exchange of user identity information between identity domains or IT systems. Its primary purpose is to simplify user provisioning and de-provisioning, ensuring consistent identity management across disparate applications and services, which perfectly matches the scenario's requirements.
Why the other options are wrong
- A. LDAP is a protocol for accessing and maintaining distributed directory information services, but it doesn't inherently automate the *cross-domain provisioning* process itself.
- B. OIDC is an authentication layer built on OAuth 2.0, providing identity verification, not for automating the creation or deletion of user accounts across systems.
- D. SAML is primarily for federated authentication and authorization (SSO), not for automating user account lifecycle management (provisioning/de-provisioning).
System for Cross-domain Identity Management (SCIM)
SCIM is an open standard designed to automate the exchange of user identity information between identity providers and service providers, simplifying user provisioning and de-provisioning.
- Automates user lifecycle management (create, update, delete).
- Uses RESTful APIs and JSON for data exchange.
- Reduces administrative overhead and improves security consistency.
Memory trick: SCIM: Syncing Cross-Identity Management.