Framework of policies and technologies ensuring the right people have appropriate access to resources.
Identity and Access Management (IAM) is the discipline ensuring the right individuals have appropriate access to technology resources. IAM encompasses identity lifecycle management (provisioning, changes, deprovisioning), authentication (verifying who someone is), authorisation (determining what they can access), and governance (ensuring access remains appropriate). Modern IAM includes single sign-on, multi-factor authentication, privileged access management, and identity governance. Effective IAM is fundamental to security and compliance.
Why It Matters
The DSC Perspective:
IAM is foundational to security—if you can't control who accesses what, you can't protect anything. Poor IAM leads to excessive access, orphaned accounts, and breach exposure. Invest in IAM capabilities.
