Identity and Access Management (IAM)
Domain 5 covers controlling physical and logical access, designing identification and authentication, federation, authorization models, and managing the identity life cycle from provisioning to deprovisioning. NIST's 2025 revision of its authentication guideline changed several long-standing password habits.
Authentication
Factors are counted by category: something you know, have or are. NIST SP 800-63B-4 sets modern password rules and distinguishes phishing-resistant authenticators from those whose codes can be relayed.
Federation and single sign-on
Single sign-on and federation let one identity provider vouch for a user to many relying services. OAuth 2.0 is an authorization framework that issues access tokens, while Kerberos provides ticket-based authentication inside a realm.
Authorization models
The outline lists RBAC, rule-based, MAC, DAC, ABAC and risk-based access control, plus policy decision and enforcement points. The classic distinction is who can change access: the owner under DAC, only the system policy under MAC.
Identity and access life cycle
Accounts are requested, approved, provisioned, reviewed, modified on transfer and removed on departure. Privileged and service accounts need extra care because they are high-value targets.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.