Skip to main content

Identity & Access Management

Description

Identity & Access Management represents the capability responsible for managing digital identities and authentication across the Scheol Lab environment.

It ensures that users and services are properly authenticated and that access privileges are assigned according to security policies.


Asset Identification

AttributeValue
Asset IDBUS-IDM-01
CI TypeBusiness
Asset NameIdentity & Access Management
Asset CategorySecurity Governance Capability
OwnerSecurity Role (Sec)
StatusPlanned
LocationInternal infrastructure
Primary FunctionCentralized authentication and identity lifecycle management

Asset Dependencies

Dependency TypeAssetStatus
PlatformIdentity Management PlatformPlanned
InfrastructureProxmox HostActive

Relationships

RelationshipTarget CI
UsesIdentity Management Platform
Supports capabilitySecure Remote Access

Asset Classification

CriteriaLevel
Confidentiality🟥 High
Integrity🟥 High
Availability🟨 Medium

Criticality score: 🟥 High


Responsibilities

RoleResponsibility
Security Role (Sec)Identity governance and access policies
Operations Role (Ops)Platform deployment and maintenance

Security Controls (High-Level)

  • Identity lifecycle management
  • Role-based access control
  • Secure authentication mechanisms
  • Access monitoring

Security Considerations

Compromise of identity systems may allow unauthorized access to multiple infrastructure components.

Controls therefore emphasize authentication strength and access monitoring.

Methodological References:

  • ISO 27001 - Control 8.2 Privileged access rights.
  • NIST CSF - PR.AC Identity Management, Authentication and Access Control.
  • EBIOS RM - Identity assets.