Know
What is Identity and Access Management?
IAM covers the identity lifecycle from creation through changes and removal, along with authentication, authorization, federation, access policy, entitlement management, and governance for workforce, customer, machine, and workload identities.
Why it matters
Many attacks now use valid credentials rather than obvious malware. Weak identity controls can give attackers legitimate-looking access to high-value systems.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Scattered Spider targeted enterprise help desks and identity controls
A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.
The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.
CISA red team gained persistent access while MFA blocked access to a sensitive system
During a CISA red-team assessment, the team gained persistent network access and moved laterally, but MFA prompts prevented access to one sensitive business system. CISA also recommended EDR, modern identity practices, centralized cybersecurity data, and Zero Trust architecture.
This controlled assessment shows both the failure modes of incomplete monitoring and the practical defensive value of MFA, endpoint visibility, identity controls, and modern architecture.
Capital One data theft exploited a misconfigured cloud-facing control
The Justice Department described an intrusion into Capital One data through a misconfigured web application firewall; the case ultimately resulted in a federal conviction for computer intrusions and wire fraud.
The case demonstrates how cloud security depends on configuration, identity permissions, monitoring, and data-access controls rather than the cloud provider alone.
Federal agencies were directed to adopt Zero Trust architectures
CISA's Zero Trust Maturity Model and related federal strategy provide an implementation roadmap across identity, devices, networks, applications/workloads, and data.
Zero Trust is an architecture and operating model with concrete implementation guidance, not a single vendor product or slogan.
CISA, USDS, and FedRAMP published a Cloud Security Technical Reference Architecture
The Cloud Security Technical Reference Architecture documents shared-responsibility considerations, cloud service models, security posture, and migration guidance for secure federal cloud adoption.
It validates that cloud security is a distinct architecture and governance discipline spanning provider capabilities and customer configuration responsibilities.
Understand the mechanics
How it works
- 1
Create or establish an identity.
- 2
Authenticate the identity.
- 3
Authorize access based on policy and context.
- 4
Record access and important identity events.
- 5
Review and change entitlements as roles change.
- 6
Remove access when it is no longer required.
Practice
What to watch for
- Dormant accounts
- Excess privilege
- Weak MFA
- Unmanaged service accounts
- Orphaned identities
- Unexpected privilege changes
Perform
What to do
- 1
Validate the identity and access involved.
- 2
Revoke suspicious sessions or credentials.
- 3
Reduce unauthorized privilege.
- 4
Investigate related identity activity.
How to reduce the risk
- Lifecycle automation
- Strong authentication
- Least privilege
- Access reviews
- Privileged access controls
- Identity telemetry
Business impact
- Reduced account takeover risk
- Better access governance
- Improved compliance
- Reduced blast radius
What different roles should do
IT
- Maintain accurate lifecycle and group membership
Security
- Monitor identity threats and risky privilege
Framework & standards context
- NIST SP 800-63 Digital Identity Guidelines
- NIST CSF 2.0
Source transparency
Authoritative sources
Last reviewed: 2026-09-02