CISSP · D5 · 13%

Identity and Access Management (IAM)

Control physical and logical access through identity proofing, authentication, federation, authorization, provisioning, review, revocation, and system integration.

Provider facts checked 2026-08-03

Objective coverage

Objective 5.1 · high

Physical and logical access

Control subject access to information, systems, devices, facilities, services, and applications based on approved need.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06
Objective 5.2 · high

Identification and authentication strategy

Choose proofing, factors, passwords, tokens, biometrics, passwordless, risk-based, and contextual authentication patterns.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06
Objective 5.3 · high

Federated identity

Integrate and govern third-party, cloud, on-premises, partner, and consumer identity through standards and trust relationships.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06
Objective 5.4 · high

Authorization

Apply discretionary, mandatory, role, rule, attribute, risk, and policy-based access decisions with least privilege.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06
Objective 5.5 · high

Identity lifecycle

Provision, review, modify, disable, revoke, reconcile, and audit human, service, privileged, shared, and device identities.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06
Objective 5.6 · normal

Authentication-system implementation

Implement and integrate directories, SSO, credential management, session controls, monitoring, recovery, and resilient authentication services.

Lesson
d5-lesson
Practice pool
d5-questions
Application
cissp-s06

title: "Identity and Access Management" summary: "Governance and architecture choices for identity lifecycle, authentication, authorization, federation, and access review."

Separate the identity decisions

Identity proofing establishes a claimed identity. Identification names the subject. Authentication verifies the claimant. Authorization evaluates permitted action. Accounting records activity. Lifecycle management keeps all of these aligned with current status and business need.

Choose authentication factors, passwords, tokens, certificates, biometrics, passwordless methods, contextual signals, recovery, and session controls from risk and usability. Federation transfers trust assertions across boundaries; it requires governance of identity sources, protocols, attributes, keys, relying parties, revocation, and failure.

Authorization models include discretionary, mandatory, role-, rule-, attribute-, risk-, and policy-based controls. Apply least privilege and need-to-know while managing conflicts, toxic combinations, privileged access, emergency access, and periodic review.

Provision and revoke employees, contractors, partners, customers, services, devices, privileged identities, and shared accounts from authoritative lifecycle events. Reconcile accounts and entitlements; do not assume disabling one directory removes every session or downstream account.

Self-check

Trace a contractor from proofing and federation through role assignment, privileged elevation, access review, contract end, session revocation, account reconciliation, and audit evidence.