Identity & AccessBeginnerProgram5 validated evidence records

Identity and Access Management (IAM)

30 sec

The policies, processes, and technologies used to manage digital identities and control what they are allowed to access.

Know

What is Identity and Access Management?

IAM covers the identity lifecycle from creation through changes and removal, along with authentication, authorization, federation, access policy, entitlement management, and governance for workforce, customer, machine, and workload identities.

Why it matters

Many attacks now use valid credentials rather than obvious malware. Weak identity controls can give attackers legitimate-looking access to high-value systems.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Government / AuthoritativeGovernment advisory

Scattered Spider targeted enterprise help desks and identity controls

2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors

A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.

Why this is evidence

The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.

See the source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A
Government / AuthoritativeOperational validation

CISA red team gained persistent access while MFA blocked access to a sensitive system

2023-02-28CISACritical infrastructure

During a CISA red-team assessment, the team gained persistent network access and moved laterally, but MFA prompts prevented access to one sensitive business system. CISA also recommended EDR, modern identity practices, centralized cybersecurity data, and Zero Trust architecture.

Why this is evidence

This controlled assessment shows both the failure modes of incomplete monitoring and the practical defensive value of MFA, endpoint visibility, identity controls, and modern architecture.

See the source — CISA: CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks
Primary / ConfirmedLaw-enforcement case

Capital One data theft exploited a misconfigured cloud-facing control

2019-07-29Capital OneFinancial services

The Justice Department described an intrusion into Capital One data through a misconfigured web application firewall; the case ultimately resulted in a federal conviction for computer intrusions and wire fraud.

Why this is evidence

The case demonstrates how cloud security depends on configuration, identity permissions, monitoring, and data-access controls rather than the cloud provider alone.

See the source — U.S. Department of Justice: Seattle Tech Worker Arrested for Data Theft Involving Large Financial Services Company
Government / AuthoritativeOperational validation

Federal agencies were directed to adopt Zero Trust architectures

2021-2023CISA / U.S. Federal GovernmentFederal enterprise

CISA's Zero Trust Maturity Model and related federal strategy provide an implementation roadmap across identity, devices, networks, applications/workloads, and data.

Why this is evidence

Zero Trust is an architecture and operating model with concrete implementation guidance, not a single vendor product or slogan.

See the source — CISA: Executive Order on Improving the Nation's Cybersecurity — Zero Trust Maturity Model
Government / AuthoritativeStandard / framework

CISA, USDS, and FedRAMP published a Cloud Security Technical Reference Architecture

2022-06CISA / USDS / FedRAMPFederal cloud

The Cloud Security Technical Reference Architecture documents shared-responsibility considerations, cloud service models, security posture, and migration guidance for secure federal cloud adoption.

Why this is evidence

It validates that cloud security is a distinct architecture and governance discipline spanning provider capabilities and customer configuration responsibilities.

See the source — CISA / USDS / FedRAMP: Cloud Security Technical Reference Architecture v2.0

Understand the mechanics

How it works

  1. 1

    Create or establish an identity.

  2. 2

    Authenticate the identity.

  3. 3

    Authorize access based on policy and context.

  4. 4

    Record access and important identity events.

  5. 5

    Review and change entitlements as roles change.

  6. 6

    Remove access when it is no longer required.

Practice

What to watch for

  • Dormant accounts
  • Excess privilege
  • Weak MFA
  • Unmanaged service accounts
  • Orphaned identities
  • Unexpected privilege changes

Perform

What to do

  1. 1

    Validate the identity and access involved.

  2. 2

    Revoke suspicious sessions or credentials.

  3. 3

    Reduce unauthorized privilege.

  4. 4

    Investigate related identity activity.

How to reduce the risk

  • Lifecycle automation
  • Strong authentication
  • Least privilege
  • Access reviews
  • Privileged access controls
  • Identity telemetry

Business impact

  • Reduced account takeover risk
  • Better access governance
  • Improved compliance
  • Reduced blast radius

What different roles should do

IT

  • Maintain accurate lifecycle and group membership

Security

  • Monitor identity threats and risky privilege

Framework & standards context

  • NIST SP 800-63 Digital Identity Guidelines
  • NIST CSF 2.0

Keep learning

AuthenticationAuthorizationSSOMFAPAMIGAITDR

Source transparency

Authoritative sources

Last reviewed: 2026-09-02