CISSP #5 AAA Services Identification, Authentication, Authorization, Auditing, Accounting in 2.45 Minutes.
AAA Services
In this session, we are going to discuss AAA services.
AAA services are a critical component of any security setup. Although AAA is commonly associated with authentication systems, it is essentially a fundamental element in security. If any of these five factors is missing, the security system will be inadequate.
Identification
Authentication
Authorization
Auditing
Accounting
Are the five elements of AAA services.
Identification:
To begin the process of authentication, authorization, and accountability, a subject must first conduct identification (AAA).
Typing a login username, swiping a smartcard, etc. can be used to provide an identity. A system cannot relate an authentication factor with a person in the absence of identity.
Authentication: is the process of determining if a claimed identity is valid. Authentication demands the person to provide extra information that conforms to the claimed identity. Using a password is the most frequent type of authentication. Authentication validates the subject's identification by matching one or more criteria to a database of valid identities. Identification and authentication are frequently used in combination as a two-step procedure.
Authorization: Access must be authorized once a subject has been authenticated. The authorization procedure assures that the requested action to an item is only possible if required permissions are available. In most circumstances, the system assesses the subject, the object, and its privileges provided to the desired activity. The subject is approved if the specified activity is permitted. The subject is not approved if the specific activity is not permitted.
Auditing is the process of recording the actions of, subject and its objects, as well as the activities of application and system functions. Log files offer an audit trail that may be used to reconstruct the history of an incident, intrusion, or system failure.
Accounting is the process of reviewing, tracking, and recording a subject's behaviors in order to keep the subject responsible for their actions.
Ещё видео!