• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Identity & Access Management
    On this page
    fingerprint

    Identity & Access Management

    Authentication, authorization, and federation concepts underpinning who can access what, and how that trust is established.

    rule_settings

    MAC vs. DAC vs. RBAC: Access Control Models Compared

    A comparison of Mandatory, Discretionary, and Role-Based access control models — the criteria each uses to grant permissions, and their …

    lock_person

    Access Control

    The policies and technical means that verify a subject's privileges before allowing or denying access to a protected object.

    compare_arrows

    Authentication vs. Authorization

    Why verifying who a user is (authentication) and deciding what they can do (authorization) are distinct, sequential steps in access control.

    fingerprint

    FIDO (Fast IDentity Online)

    A passwordless authentication standard that uses biometrics and public-key cryptography to replace vulnerable, phishable passwords.

    admin_panel_settings

    Identity Provider (IdP)

    The trusted authority that authenticates users and issues the assertions or tokens that relying service providers use to grant access.

    token

    JWT (JSON Web Token)

    An open, JSON-based standard (RFC 7519) for representing claims securely between parties, widely used for stateless authentication and SSO.

    confirmation_number

    Kerberos

    A ticket-based network authentication protocol, developed at MIT, that establishes mutual trust between a client and a service through an …

    vpn_key

    OAuth 2.0

    An open authorization framework that lets a resource owner securely delegate access to their resources to a third-party client application.

    swap_horizontal_circle

    OAuth 2.0 and OIDC

    How OAuth 2.0's delegated-authorization model and the OpenID Connect identity layer built on top of it divide the work of authorization and …

    badge

    OpenID Connect (OIDC)

    An identity layer built on top of OAuth 2.0 that adds standardized user authentication via a signed ID Token.

    passkey

    Passkey

    A cloud-synced FIDO2 credential that completes the shift to passwordless authentication across a user's devices.

    handshake

    SAML (Security Assertion Markup Language)

    An XML-based open standard for exchanging authentication data between an identity provider and a service provider, the de facto standard for …

    login

    Single Sign-On (SSO)

    An authentication approach that lets a user log in once with one identity to reach multiple applications and services.

    account_tree

    Active Directory (AD)

    Microsoft's directory service for centrally managing users, computers, groups, and resources, and for controlling authentication and access …

    dns

    LDAP (Lightweight Directory Access Protocol)

    The standard protocol for querying and maintaining a hierarchical directory service that stores information about users, devices, and other …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs