certslothcertsloth
CISSP/Topic 14

ISC2 / Professional

Identity Assurance and Access Models

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Proof the identity, bind the credential, limit the session.

Must remember

Identity proofing verifies a claimed real-world identity before enrollment. Authentication later verifies control of its bound authenticator. Strong authentication of a fraudulently enrolled identity does not repair poor proofing. Match identity and authenticator assurance to the transaction's risk.

Federation separates an identity provider from relying parties. Validate issuer, audience, signature, time bounds and replay protections for assertions/tokens. SSO simplifies access but centralizes dependency on the identity provider; design recovery and account protection accordingly. Session expiration, revocation and reauthentication matter after login.

RBAC maps permissions to job functions; ABAC evaluates subject, object and environment attributes; mandatory access applies centrally imposed labels; discretionary access permits owner-controlled delegation. Rule-based access applies defined rules and is not synonymous with role-based access. Risk-based decisions can adjust controls using context, but signals must be trustworthy and explainable.

Separation of duties may be static (never hold both roles) or dynamic (do not perform both actions in one transaction). Privileged access should use named identities, least privilege, just-in-time elevation and audit. Shared credentials weaken attribution unless tightly controlled by a system that records individual use.

For biometrics, false acceptance admits an impostor and false rejection blocks a legitimate user. The crossover/equal-error point is one comparison metric, not the whole deployment decision. Consider spoof resistance, accessibility, privacy and recovery.

Machine identities include workloads, devices and services. Inventory owners, credential issuance, rotation, permissions and decommissioning. Federation or short-lived credentials often reduces distributed secret management, but token issuance itself becomes a critical trust boundary.

Choose under exam pressure

Requirement Choice and reason
High-risk enrollment Appropriate identity proofing before authenticator binding.
Compromised federation token Revoke/contain sessions and investigate issuer/validation, not only reset a password.
Sensitive payment approval Separate initiation and approval authorities.

Traps

  • Successful MFA does not prove the enrolled person was correctly identified.
  • A validly signed token with the wrong audience must still be rejected.

Active recall

1. Proofing versus authentication?

Proofing establishes a claimed identity; authentication verifies its bound authenticator later.

2. Why validate token audience?

To reject a token issued for a different relying party or resource.

3. What is dynamic separation of duties?

Preventing conflicting actions within a transaction or session even if a person has broader eligible roles.

4. Which biometric error admits an impostor?

False acceptance.

5. Why include workload identities in access reviews?

They can hold persistent, powerful access without normal human joiner/leaver processes.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.