ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A company is implementing a new system for managing access to its internal network resources. They want a robust system that can centralize user identities, authenticate users across various applications, and manage authorizations efficiently. Which security solution is designed to address these combined needs comprehensively?

  1. AIdentity and Access Management (IAM)
  2. BPhysical Access Control System (PACS)
  3. CSingle Sign-On (SSO)
  4. DMulti-Factor Authentication (MFA)
Show answer & explanation

Correct answer: A. Identity and Access Management (IAM)

Identity and Access Management (IAM) is a comprehensive framework that includes policies, processes, and technologies to manage digital identities and control user access to resources. It encompasses centralized identity management, authentication, and authorization across multiple systems.

Why the other options are wrong

  • B. PACS deals with physical entry to buildings, not logical access to network resources.
  • C. SSO allows users to log in once for multiple applications, but it's a component of IAM, not the overarching solution.
  • D. MFA is an authentication method, not a complete system for identity and authorization management.

Identity and Access Management (IAM)

A framework of policies, processes, and technologies that manage digital identities and control user access to resources across an enterprise.

  • Centralizes user identity information.
  • Manages authentication and authorization.
  • Ensures appropriate access to resources.

Memory trick: IAM is like the central brain for all your user identities and their access permissions.

More Access Controls Concepts questions