Chapter 5 of 813% of exam

Identity and Access Management (IAM)

Domain 5 covers controlling physical and logical access, designing identification and authentication, federation, authorization models, and managing the identity life cycle from provisioning to deprovisioning. NIST's 2025 revision of its authentication guideline changed several long-standing password habits.

Authentication

Factors are counted by category: something you know, have or are. NIST SP 800-63B-4 sets modern password rules and distinguishes phishing-resistant authenticators from those whose codes can be relayed.

Password length
At least 15 characters for passwords used as a single factor; at least 8 when used only within multi-factor authentication.
NIST SP 800-63B-4 §3.1.1.2
No composition or rotation rules
No character-mix rules and no periodic changes; force a change on evidence of compromise and check against a blocklist.
NIST SP 800-63B-4 §3.1.1.2
Phishing resistance
Manually entered OTP and out-of-band codes are not phishing-resistant; channel binding (e.g., PIV/CAC) or verifier name binding (e.g., WebAuthn) are.
NIST SP 800-63B-4 §3.2.5
Authentication fatigue
Approve-only push prompts are no longer acceptable; the secret must be transferred between the out-of-band device and the primary channel.
NIST SP 800-63B-4 §3.1.3

Federation and single sign-on

Single sign-on and federation let one identity provider vouch for a user to many relying services. OAuth 2.0 is an authorization framework that issues access tokens, while Kerberos provides ticket-based authentication inside a realm.

OAuth 2.0
A client obtains an access token from an authorization server to reach protected resources on the resource owner's behalf, without the owner's credentials.
RFC 6749
Kerberos tickets
A ticket-granting ticket from the authentication service is used to obtain service tickets.
RFC 4120
Kerberos clocks
Clocks must be loosely synchronized because timestamps are checked within a clock-skew window to detect replay.
RFC 4120 §3.2.3

Authorization models

The outline lists RBAC, rule-based, MAC, DAC, ABAC and risk-based access control, plus policy decision and enforcement points. The classic distinction is who can change access: the owner under DAC, only the system policy under MAC.

MAC
Compares security labels with clearances; an entity cannot by its own volition grant others access.
RFC 4949
DAC
Access based on identity, with an owner who may grant and revoke access rights.
RFC 4949
ABAC
Evaluates attributes of subject, object and environment against policy.
NIST SP 800-162
Risk-based
Dynamic policy can weigh behavioral and environmental signals such as location, time and device state.
NIST SP 800-207 §2.1

Identity and access life cycle

Accounts are requested, approved, provisioned, reviewed, modified on transfer and removed on departure. Privileged and service accounts need extra care because they are high-value targets.

Account management
Notify account managers on termination or transfer, review accounts periodically, and align account management with personnel processes.
NIST SP 800-53 Rev. 5 AC-2
Transfers
On reassignment, review whether existing access is still needed.
NIST SP 800-53 Rev. 5 PS-5
Privileged use
Log the execution of privileged functions, and have administrators use non-privileged accounts for non-security tasks.
NIST SP 800-53 Rev. 5 AC-6(9), AC-6(2)
Reauthentication at AAL3
The overall reauthentication timeout at AAL3 is no more than 12 hours.
NIST SP 800-63B-4 §2.3.3

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report