Account Management
The figure below shows further detail on the never-ending cycle that ensures proper access control.
4 slides · 2 min read · Domain 6
Text on this slide
Identity Provisioning/ Establish Access Privileges
New Identity Request
Job/Duties Change Review
Disable and Deprovision User Behaviour Review
System, App Logs
Identity Store Access Accounting
Authentication (Per Access Attempt)
Authorization (Per Access Attempt)
Accounting (During/After Asset Access)
- The identity store provides a centralized
- Systems and applications logs, repository of all information pertaining security monitoring systems and to a given identity that is known to the agents, and other sensors may record organization. This is initially built as part indicators that result from actions of validating the claim to identity (of taken by users as they attempt to or are granted access to resources.
the person or a nonhuman user) and is updated when changes to that identity
- User behavior modeling may detect
are made. The identity store also contains additional indicators that may need records of decisions made to grant, investigation, which can trigger user
downgrade, or remove permissions for an
account reviews that may lead to identity.
follow-on decisions to modify the access
- The integrated identity and access
privileges granted to that user. management system (represented
- Changes in jobs, special tasks assigned
by the three databases in the middle or completed, or other changes affecting of the figure) maintains its databases a user's assigned duties often lead to of authentication and authorization changes in access privileges that are information, recording both permissions, granted to that user.
access requests, grants, and authorization requests and grants.
- At some point, all users leave the
(This is the third "A" of the "AAA"
organization; their accesses are disabled, acronym for the set of access control deprovisioned, and finally deleted from functions of the IAM system.) the active systems records.
Audit or detailed examination of these various information sources provides a rich set of data upon which systems security assessments can be made.
