Chapter 12.  Day 12 – Identity and Access Management - Access Management, Provisioning, and Attacks

This chapter covers foundational concepts in the access and accountability layers of the Identity and Access Management(IAM) domain.

A candidate appearing for the CISSP exam is expected to understand the foundational concepts and have knowledge of the following key areas of the identity and access management domain:

  • Access management
  • Authorization mechanisms
  • The identity and provisioning lifecycle
  • Preventing or mitigating access control attacks

An overview of access management

Observe the following illustration. Access management is facilitated through authentication and authorization processes. Each of these processes consists of various concepts and techniques. From an information security perspective, there are process-centric threats, vulnerabilities attacks, and counter measures that need to be understood:

An overview of access management

In this module, you will understand the following:

  • Access control concepts, methodologies, and techniques
  • Authorization mechanisms
  • The identity and provisioning lifecycle
  • Preventing or mitigating access control attacks
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.142.194.230