What the discipline covers.
WHAT IT ADDRESSES
Establishing who someone is, and controlling what they may do.
WHAT THE TWO PARTS ARE
Authentication: proving identity
Authorisation: determining permission
WHY THE DISTINCTION MATTERS
Being who you claim is not the same as being permitted, and confusing them produces serious errors.
WHAT IDENTITY AND ACCESS MANAGEMENT INVOLVES
Creating and removing accounts Verifying identity at sign-in Granting and revoking permissions Recording what was accessed Reviewing whether access remains appropriate
WHY IT MATTERS
Access determines what a compromised account or a departing employee can reach.
WHAT MOST ORGANISATIONS GET WRONG
Access accumulates and is never removed Accounts persist after people leave Permissions are copied from someone else Nobody knows who has what
WHY ACCUMULATION IS THE CENTRAL PROBLEM
People change roles and gain access; they rarely lose it.
WHAT THAT PRODUCES
Individuals with far more reach than their role requires.
WHAT THAT MEANS FOR RISK
A single compromised account reaches everything that person accumulated.
WHAT TO ESTABLISH FIRST
What accounts exist and what they can reach.
WHY
Nothing can be controlled that is not known.
WHAT TO TREAT THIS CATEGORY AS
Practical guidance, scaled from small businesses to larger organisations.