1
00:00:00,000 --> 00:00:01,230
In this section of the course,

2
00:00:01,230 --> 00:00:02,580
we're going to cover Identity

3
00:00:02,580 --> 00:00:04,680
and Access Management Solutions.

4
00:00:04,680 --> 00:00:08,250
Identity and Access Management, also known as IAM,

5
00:00:08,250 --> 00:00:11,580
is a crucial component of information security that ensures

6
00:00:11,580 --> 00:00:13,740
that the right individuals have access

7
00:00:13,740 --> 00:00:15,810
to the right resources at the right times

8
00:00:15,810 --> 00:00:17,700
for the right reason.

9
00:00:17,700 --> 00:00:20,700
Identity and access management technologies provide tools

10
00:00:20,700 --> 00:00:23,580
for business processes that facilitate the management

11
00:00:23,580 --> 00:00:26,880
of electronic identities, including password management,

12
00:00:26,880 --> 00:00:28,110
network access control,

13
00:00:28,110 --> 00:00:30,423
and the management of digital identities.

14
00:00:31,290 --> 00:00:33,900
Identity and access management focuses on the security

15
00:00:33,900 --> 00:00:36,870
controls, identification techniques, access controls,

16
00:00:36,870 --> 00:00:39,240
and account management to ensure

17
00:00:39,240 --> 00:00:41,370
that only authorized users have access

18
00:00:41,370 --> 00:00:43,542
to specific resources and data.

19
00:00:43,542 --> 00:00:46,710
An identity and access management system usually consists

20
00:00:46,710 --> 00:00:49,560
of four main processes, which are identification,

21
00:00:49,560 --> 00:00:53,400
authentication, authorization, and accounting.

22
00:00:53,400 --> 00:00:55,410
First, we have identification.

23
00:00:55,410 --> 00:00:56,820
Identification is the process

24
00:00:56,820 --> 00:00:59,430
where a user claims an identity, usually in the form

25
00:00:59,430 --> 00:01:01,980
of a username or an email address.

26
00:01:01,980 --> 00:01:04,379
Second, we have authentication.

27
00:01:04,379 --> 00:01:07,260
Authentication is a process of verifying the identity

28
00:01:07,260 --> 00:01:10,080
of a user, device or system.

29
00:01:10,080 --> 00:01:12,390
Third, we have authorization.

30
00:01:12,390 --> 00:01:13,770
Once a user's authenticated,

31
00:01:13,770 --> 00:01:16,140
the authorization process determines what permissions

32
00:01:16,140 --> 00:01:18,930
or levels of access that user has.

33
00:01:18,930 --> 00:01:20,343
Fourth, we have accounting.

34
00:01:21,368 --> 00:01:22,620
Accounting, also known as auditing,

35
00:01:22,620 --> 00:01:23,880
is the process of tracking

36
00:01:23,880 --> 00:01:26,130
and recording user activities for the purpose

37
00:01:26,130 --> 00:01:29,580
of compliant security monitoring and historical records.

38
00:01:29,580 --> 00:01:31,410
So in this section of the course,

39
00:01:31,410 --> 00:01:33,690
we will be focused on domain two and domain four,

40
00:01:33,690 --> 00:01:37,920
specifically objectives 2.4 and objective 4.6.

41
00:01:37,920 --> 00:01:41,040
Objective 2.4 states that given a scenario, you must be able

42
00:01:41,040 --> 00:01:43,980
to analyze indicators of malicious activity.

43
00:01:43,980 --> 00:01:46,590
Objective 4.6 states that given a scenario,

44
00:01:46,590 --> 00:01:48,330
you must be able to implement

45
00:01:48,330 --> 00:01:51,180
and maintain identity and access management.

46
00:01:51,180 --> 00:01:52,650
First, we will cover identity

47
00:01:52,650 --> 00:01:55,380
and access management, including its four main processes

48
00:01:55,380 --> 00:01:57,120
and concepts of provisioning

49
00:01:57,120 --> 00:02:00,420
and deprovisioning of user accounts, identity proofing,

50
00:02:00,420 --> 00:02:03,480
interoperability, and attestation.

51
00:02:03,480 --> 00:02:05,520
Next, we're going to jump into discussion

52
00:02:05,520 --> 00:02:08,910
of multi-factor authentication, also known as MFA.

53
00:02:08,910 --> 00:02:11,250
Here, we would discuss the authentication factors

54
00:02:11,250 --> 00:02:14,130
of something you know, something you have,

55
00:02:14,130 --> 00:02:18,210
something you are, something you do, and somewhere you are.

56
00:02:18,210 --> 00:02:21,706
And we will also cover the different multi-factor

57
00:02:21,706 --> 00:02:23,100
authentication implementations, including the use

58
00:02:23,100 --> 00:02:25,260
of biometrics, hard tokens,

59
00:02:25,260 --> 00:02:28,890
and soft tokens, security keys, and pass keys.

60
00:02:28,890 --> 00:02:31,440
Then, we're going to talk about password security.

61
00:02:31,440 --> 00:02:33,960
Well, we will discuss different password policy

62
00:02:33,960 --> 00:02:36,570
best practices that you should be aware of, as well as how

63
00:02:36,570 --> 00:02:39,900
to use password managers and passwordless authentication

64
00:02:39,900 --> 00:02:43,140
in your modern identity and access management systems.

65
00:02:43,140 --> 00:02:44,520
After that, we're going to discuss

66
00:02:44,520 --> 00:02:45,930
some common password attacks,

67
00:02:45,930 --> 00:02:48,990
including password spraying attacks, brute force attacks,

68
00:02:48,990 --> 00:02:51,330
dictionary attacks, and hybrid attacks, as well

69
00:02:51,330 --> 00:02:53,190
as performing a quick demonstration to show you

70
00:02:53,190 --> 00:02:56,250
how an attacker might conduct a password cracking attack

71
00:02:56,250 --> 00:02:58,410
against your credentials.

72
00:02:58,410 --> 00:03:00,870
Next, we're going to discuss single sign-on.

73
00:03:00,870 --> 00:03:03,210
Single sign-on, also known as SSO,

74
00:03:03,210 --> 00:03:05,460
is a user authentication service that allows a user

75
00:03:05,460 --> 00:03:08,460
to use one set of login credentials, like a name

76
00:03:08,460 --> 00:03:11,520
and password to access multiple applications using various

77
00:03:11,520 --> 00:03:15,210
technologies like LDAP, OAuth and SAML.

78
00:03:15,210 --> 00:03:18,000
Then, we will go over federations.

79
00:03:18,000 --> 00:03:21,120
A federation is a process that allows for the sharing

80
00:03:21,120 --> 00:03:24,540
and use of identities across multiple information systems

81
00:03:24,540 --> 00:03:27,900
or organizations to enable users to access different systems

82
00:03:27,900 --> 00:03:30,120
with a single set of credentials.

83
00:03:30,120 --> 00:03:33,720
After that, we will dive into privileged access management.

84
00:03:33,720 --> 00:03:35,010
Privileged access management,

85
00:03:35,010 --> 00:03:38,220
or PAM, involves the use of just-in-time permissions,

86
00:03:38,220 --> 00:03:40,560
password vaulting, and temporal accounts

87
00:03:40,560 --> 00:03:44,640
to gain administrative access over a given system or device.

88
00:03:44,640 --> 00:03:46,950
Then, we'll discuss access control models,

89
00:03:46,950 --> 00:03:49,080
including mandatory access control,

90
00:03:49,080 --> 00:03:52,380
discretionary access control, role-based access control,

91
00:03:52,380 --> 00:03:53,760
rule-based access control,

92
00:03:53,760 --> 00:03:57,120
and attribute-based access control, as well as a discussion

93
00:03:57,120 --> 00:03:58,650
of time of day restrictions

94
00:03:58,650 --> 00:04:00,360
and how to implement the concept

95
00:04:00,360 --> 00:04:02,850
of least privilege in your system.

96
00:04:02,850 --> 00:04:05,190
Next, we will cover assigning permissions

97
00:04:05,190 --> 00:04:07,920
and how you can best go about the process better

98
00:04:07,920 --> 00:04:09,720
to secure organization.

99
00:04:09,720 --> 00:04:12,150
And finally, we will take a short quiz to see

100
00:04:12,150 --> 00:04:14,070
what you learned during this section of the course,

101
00:04:14,070 --> 00:04:16,680
and review each of those quiz questions to fully ensure

102
00:04:16,680 --> 00:04:19,142
that you can explain why each answer was right.

103
00:04:20,010 --> 00:04:22,050
So if you're ready to dive into the world

104
00:04:22,050 --> 00:04:24,960
of digital identities, let's begin our coverage of identity

105
00:04:24,960 --> 00:04:27,030
and access management solutions in this section

106
00:04:27,030 --> 00:04:27,863
of the course.

