2 cissp ® Official Study Guide Eighth Edition


Understand the difference between identification and authentication



Download 19,3 Mb.
Pdf ko'rish
bet580/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   576   577   578   579   580   581   582   583   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Understand the difference between identification and authentication.
Access controls 
depend on effective identification and authentication, so it’s important to understand the 
differences between them. Subjects claim an identity, and identification can be as simple as 
a username for a user. Subjects prove their identity by providing authentication credentials 
such as the matching password for a username.
Understand the difference between authorization and accountability.
After authenticat-
ing subjects, systems authorize access to objects based on their proven identity. Auditing 
logs and audit trails record events including the identity of the subject that performed an 
action. The combination of effective identification, authentication, and auditing provides 
accountability.
Understand the details of the primary authentication factors.
The three primary fac-
tors of authentication are something you know (such as a password or PIN), something 
you have (such as a smartcard or token), and something you are (based on biometrics). 
Multifactor authentication includes two or more authentication factors, and using it is more 
secure than using a single authentication factor. Passwords are the weakest form of authen-
tication, but password policies help increase their security by enforcing complexity and
history requirements. Smartcards include microprocessors and cryptographic certificates, 
and tokens create onetime passwords. Biometric methods identify users based on charac-
teristics such as fingerprints. The crossover error rate identifies the accuracy of a biometric 
method. It shows where the false rejection rate is equal to the false acceptance rate.
Understand single sign-on.
Single sign-on (SSO) is a mechanism that allows subjects to 
authenticate once and access multiple objects without authenticating again. Kerberos is the 
most common SSO method used within organizations, and it uses symmetric cryptography 
and tickets to prove identification and provide authentication. When multiple organizations 
want to use a common SSO system, they often use a federated identity management system, 
where the federation, or group of organizations, agrees on a common method of authenti-
cation. Security Assertion Markup Language (SAML) is commonly used to share federated 
identity information. Other SSO methods are scripted access, SESAME, and KryptoKnight. 
OAuth and OpenID are two newer SSO technologies used on the internet. OAuth 2.0 is 
recommended over OAuth 1.0 by many large organizations such as Google.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   576   577   578   579   580   581   582   583   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish