### AAA Framework
The [[Identity]] and access management (**IAM**) domain focuses on keeping data secure. It does this by ensuring user identities are **trusted** and **authenticated** and that access to physical and logical assets is **authorised** and monitor and log user actions for **accountability**. This helps prevent unauthorised users, while allowing authorised users to perform their tasks.
Essentially, IAM uses what is referred to as the principle of *least privilege*, which is the concept of granting only the minimal access and authorisation required to complete a task. As an example, a cybersecurity analyst might be asked to ensure that customer service representatives can only view the private data of a customer, such as their phone number, while working to resolve the customer's issue; then remove access when the customer's issue is resolved.
A key way to *create a secure environment that supports a defence strategy* is implementing two fundamental security principles that limit access to organisational resources:
- The **principle of least privilege** in which a user is only granted the minimum level of access and authorisation required to complete a task or function.
- **Separation of duties**, which is the principle that users should not be given levels of authorisation that would allow them to misuse a system.
Both principles typically support each other. For example, according to [[Principle of Least Privilege|least privilege]], a person who needs permission to approve purchases from the IT department shouldn't have the permission to approve purchases from every department. Likewise, according to separation of duties, the person who can approve purchases from the IT department should be different from the person who can input new purchases.
In other words, *least privilege limits the access that an individual receives*, while *separation of duties divides responsibilities among multiple people* to prevent any one person from having too much control.
### [[User Provisioning]]
### [[Access Control Schemes]]