ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium
A security engineer is configuring a new system where user provisioning needs to be highly automated and standardized across various cloud applications. The goal is to reduce manual effort and ensure consistency in identity data exchange. Which open standard is specifically designed to facilitate automated user provisioning and deprovisioning between identity providers and service providers?
- ASCIM (System for Cross-domain Identity Management)
- BOAuth 2.0
- COpenID Connect (OIDC)
- DSAML (Security Assertion Markup Language)
Show answer & explanationAnswer & explanation
Correct answer: A. SCIM (System for Cross-domain Identity Management)
SCIM is an open standard that automates the exchange of user identity information between identity providers (like directories) and service providers (like cloud applications), directly addressing the need for automated and standardized provisioning.
Why the other options are wrong
- B. OAuth 2.0 is an authorization framework that allows third-party applications to access user data without exposing credentials, but it does not handle user provisioning and deprovisioning.
- C. OpenID Connect is an authentication layer built on OAuth 2.0, primarily for identity verification, not for managing user accounts and attributes.
- D. SAML is used for authentication and authorization (Single Sign-On), not for automated user provisioning.
SCIM (System for Cross-domain Identity Management)
An open standard that defines a schema for user and group management, and a REST API for automated provisioning and deprovisioning of identities between systems.
- Reduces manual identity management tasks.
- Ensures consistency of identity data.
- Supports integration between cloud and on-premise systems.
Memory trick: SCIM Syncs Cloud Identities Seamlessly