Access management
Also known as: identity and access management, IAM
The rules and routines that decide who may use which data and systems, and that keep those rights correct over time.
Draft - this entry has not been reviewed yet.
Formal
The ongoing process of granting, reviewing and removing each user account's rights to data and systems, based on the holder's role and approved need, so that access control always enforces a decision that still holds.
In plain English
Like the office manager who decides who gets a key to which rooms, and collects the keys back when someone changes job or leaves.
In practice
When a case officer in a municipality moves from social services to the payroll office, IT removes her access to citizens' case files the same week and grants payroll access, approved by her new manager.
Why it matters
Rights pile up quietly as people change roles; if nobody reviews them, one stolen account can open far more than its owner ever needed.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Name an owner for access management, and appoint a data or system owner for each important system who decides who may use it.
- List every user, admin, service and guest account per system, and link each account to a named person or owner.
- Define roles from job functions with the rights each role needs, and write down forbidden combinations, such as creating suppliers and approving payments to them.
- Connect the HR system to the directory so joiners, movers and leavers trigger account creation, change and removal, using SCIM or connectors where possible.
- Require the manager's approval for any right beyond the role's standard access, and log who approved what and when.
- On a job change, remove the old role's rights in the same step as granting the new ones; on departure, disable the account on the last day and revoke tokens, keys and local accounts.
- Run access reviews at least yearly, and quarterly for admin roles and sensitive systems, where owners confirm or remove each right and the result is recorded.
- Report orphaned accounts, removed rights and overdue reviews to management, and fix the process where the numbers show gaps.
Common pitfalls
- Adding rights when people change jobs without removing the old ones, so privileges pile up over the years.
- Rubber-stamp reviews where owners approve long lists of cryptic group names they do not understand.
- Disabling only the directory account when someone leaves and forgetting local application accounts, API keys and active sessions.
Good guides
- Identity and access management - 10 Steps to Cyber Security(opens in a new tab) · NCSC UK
- CIS Critical Security Control 6 - Access Control Management(opens in a new tab) · Center for Internet Security
- What are access reviews? - Microsoft Entra ID Governance(opens in a new tab) · Microsoft
- Cyberforsvar der virker(opens in a new tab) · Center for Cybersikkerhed (Styrelsen for Samfundssikkerhed) (in Danish)
- Referencearkitektur for brugerstyring(opens in a new tab) · Digitaliseringsstyrelsen (in Danish)
Technical deep dive
Access management is usually modelled as an identity lifecycle: joiner, mover, leaver (JML). An authoritative source, typically the HR system, emits events that an identity governance and administration (IGA) platform turns into provisioning actions in directories and applications, today often over SCIM 2.0 (RFC 7643 for the schema, RFC 7644 for the protocol) or through connectors to Active Directory and Entra ID. The mover case is where most programmes fail: new rights are added promptly because someone needs them to work, but old rights are rarely removed, so accumulated privilege ("privilege creep") grows with tenure. Leaver processing has its own traps - disabling the directory account does not revoke local application accounts, API keys, OAuth refresh tokens or already-issued session cookies.
The authorisation model sits underneath. Role-based access control (RBAC, standardised as ANSI/INCITS 359) bundles permissions into roles derived from job functions; attribute-based access control (ABAC, NIST SP 800-162) evaluates policies over attributes of subject, object, action and environment at request time. Real estates are hybrids: coarse RBAC for birthright access, ABAC or fine-grained entitlements for sensitive data, and just-in-time elevation through privileged access management (PAM) for administrator rights. Segregation of duties (SoD) rules - for instance that nobody may both create a supplier and approve payments to it - are expressed as toxic role combinations that the IGA tool blocks or flags.
Assurance comes from periodic access reviews (recertification), in which data or system owners confirm or revoke each entitlement. Reviews degrade into rubber-stamping when owners are shown thousands of cryptic group names; effective programmes review by business role, highlight deviations from peer groups and track revocation rates. Orphaned accounts (no living owner), shared accounts and service accounts with non-expiring secrets are standard audit findings.
In control frameworks the topic is split across several controls: ISO/IEC 27002:2022 5.15 (access control), 5.16 (identity management), 5.17 (authentication information), 5.18 (access rights) and 8.2 (privileged access rights); CIS Controls v8 Control 5 (Account Management) and Control 6 (Access Control Management), where Safeguards 6.1 and 6.2 require documented processes for granting and revoking access. NIS2 Art. 21(2)(i) names access control policies explicitly. Access management should be distinguished from authentication (proving who someone is) and from access control as an enforcement mechanism: it is the governance process that decides what the enforcement point should enforce.
What to learn first
Everything this builds on, foundations first.
- Digital identity
- →Credential
- →Authentication
- →Authorization
- →Access management
Relationships
- A kind of
- Security control
- Consists of
- Privileged access management (PAM)
- Requires
- AuthenticationAuthorization
- Implements
- Access control
- Implemented by
- Cloud IAM
- Don't confuse with
- Access control
- Mandated by
- CIS Controls
Sources & further reading
Standards & official texts
- CIS Critical Security Controls v8 - Controls 5 and 6 · Center for Internet Security
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…