Definition

integrated access management (IAM)

Part of the Authentication glossary:

Integrated access management (IAM) is a combination of business processes, policies and technologies that allows organizations to provide secure access to confidential data. IAM software is used by enterprises to control the flow of sensitive data in and out of the network.

Effective integrated access management tools incorporate four elements:

  • A method of providing users access to applications, systems and documents throughout an enterprise that are required for individual job function.
  • The ability to authenticate a user at the proper access level, based upon the principle of least privilege (POLP).
  • A single sign-on (SSO) that easily allows users to access resources to which they have been granted access.
  • A means to generate an audit trail to confirm the IAM system is working properly and meet compliance requirements.

Security experts recommend the use of multifactor authentication (MFA) to validate user identity, including biometric data, smart cards and RFID chips.

Learn more about IT: 
Security expert Joel Dubin exposes IAM blunders this tip about worst practices. 

> You can download a free chapter from "Security Assessment: Case Studies for Implementing the NSA IAM."

Joel Dubin explains how anonymous credentials and selective disclosure certificates affect enterprise IAM.

Joel Dubin explains how multifactor authentication works in IAM suites

This was last updated in October 2008
Posted by: Margaret Rouse

Related Terms

Definitions

  • invocation ID

    - An invocation ID is an ID number that identifies databases within Active Directory and changes as AD is in a restore process. Invocation IDs change during the restore process to make sure replicati... (SearchWindowsServer.com)

  • TAN (transaction authentication number)

    - A transaction authentication number (TAN) is a type of single-use password used for an online banking transaction in conjunction with a standard ID and password. TANs are often in a list made by a... (WhatIs.com)

  • social login

    - Social login is a single sign-on (SSO) that allows users to authenticate themselves on various applications and sites by connecting through a social networking site rather than typing a separate ID... (WhatIs.com)

Glossaries

  • Authentication

    - Terms related to authentication, including security definitions about passwords and words and phrases about proving identity.

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question About integrated access management (IAM)Powered by ITKnowledgeExchange.com

Get answers from your peers on your most technical challenges

Tech TalkComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.