What is integrated access management (IAM)? - Definition from WhatIs.com

Definition

integrated access management (IAM)

Part of the Authentication glossary:

Integrated access management (IAM) is a combination of business processes, policies and technologies that allows organizations to provide secure access to confidential data. IAM software is used by enterprises to control the flow of sensitive data in and out of the network.

Effective integrated access management tools incorporate four elements:

  • A method of providing users access to applications, systems and documents throughout an enterprise that are required for individual job function.
  • The ability to authenticate a user at the proper access level, based upon the principle of least privilege (POLP).
  • A single sign-on (SSO) that easily allows users to access resources to which they have been granted access.
  • A means to generate an audit trail to confirm the IAM system is working properly and meet compliance requirements.

Security experts recommend the use of multifactor authentication (MFA) to validate user identity, including biometric data, smart cards and RFID chips.

Learn more about IT: 
Security expert Joel Dubin exposes IAM blunders this tip about worst practices. 

> You can download a free chapter from "Security Assessment: Case Studies for Implementing the NSA IAM."

Joel Dubin explains how anonymous credentials and selective disclosure certificates affect enterprise IAM.

Joel Dubin explains how multifactor authentication works in IAM suites

This was last updated in October 2008
Posted by: Margaret Rouse

Related Terms

Definitions

  • claims-based identity

    - Claims-based identity is a means of authenticating an end user, application or device to another system in a way that abstracts the entity’s specific information while providing data that authorize... (WhatIs.com)

  • inherence factor

    - The inherence factor, in a security context, is a category of user authentication credentials consisting of elements that are integral to the individual in question, in the form of biometric data. (WhatIs.com)

  • possession factor

    - The possession factor, in a security context, is a category of user authentication credentials based on items that the user has with them, typically a hardware device such as a security token or a ... (WhatIs.com)

Glossaries

  • Authentication

    - Terms related to authentication, including security definitions about passwords and words and phrases about proving identity.

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question About integrated access management (IAM)Powered by ITKnowledgeExchange.com

Get answers from your peers on your most technical challenges

Tech TalkComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.