Difference between revisions of "Identity and Access Management"
From MgmtWiki
(→Context) |
(→Context) |
||
| Line 4: | Line 4: | ||
* Computer asset management is typically approached by listing the identifiers of real-world entities and developing some method, like [[Role Management]] to determine which computer asset can be accessed by the [[Principal]] identifier that is representative of that real-world entity. | * Computer asset management is typically approached by listing the identifiers of real-world entities and developing some method, like [[Role Management]] to determine which computer asset can be accessed by the [[Principal]] identifier that is representative of that real-world entity. | ||
* In this context [[Identity]] is taken to be the [[Identifier]]s and [[Attribute]]s held by a [[Data Controller]] in a [[User Object]]. | * In this context [[Identity]] is taken to be the [[Identifier]]s and [[Attribute]]s held by a [[Data Controller]] in a [[User Object]]. | ||
| + | ==Solutions== | ||
| + | There are many proposals for what IAM should include including one attempt at an IAM Reference Architecture.<ref>George B. Dobs, ''IAM Reference Architecture'' (2024-08) https://bok.idpro.org/article/id/76/</ref> The generic approach seems to separate the Identity Proofing from the Access control as was implemented by Kerberos. | ||
==References== | ==References== | ||
Revision as of 08:55, 16 August 2024
Full Title or Meme
Identity and Access Management is the combination of Identity Managementand Access Management.
Context
- Computer asset management is typically approached by listing the identifiers of real-world entities and developing some method, like Role Management to determine which computer asset can be accessed by the Principal identifier that is representative of that real-world entity.
- In this context Identity is taken to be the Identifiers and Attributes held by a Data Controller in a User Object.
Solutions
There are many proposals for what IAM should include including one attempt at an IAM Reference Architecture.[1] The generic approach seems to separate the Identity Proofing from the Access control as was implemented by Kerberos.
References
- ↑ George B. Dobs, IAM Reference Architecture (2024-08) https://bok.idpro.org/article/id/76/