Module 02. Identification. Authentication.
Authorization. Cornell Notes
High Level Overview
Access control ensures that the right person gets the right access at the right time for the right reason.
Principles include least privilege. separation of duties. and need to know. These limit damage from
mistakes and misuse.
Choose a control model that fits the environment. MAC. DAC. RBAC. Rule based RBAC.
Strong authentication and account lifecycle controls reduce account abuse.
Cues for Review
Key Points and Cues
●
Least privilege. Separation of duties. Need to know.
●
MAC vs DAC vs RBAC.
●
Auth factors. Something you know. Have. Are.
●
SSO. MFA. Password hygiene.
●
Provisioning and deprovisioning.
Main Notes
Principles for Safer Access
Least privilege. Grant only what is required to perform tasks.
bullet
Separation of duties. Split critical tasks so one person cannot complete the whole action alone.
bullet
Need to know. Limit data access to those with a business need.
bullet
Models of Control
MAC. Central authority sets labels and rules. Users cannot change object access.
bullet
DAC. Data owner decides who can access objects. Flexible but easier to misconfigure.
bullet
RBAC. Roles map to job functions. Users receive permissions by role membership.
bullet
Rule based RBAC. Rules adjust access based on context. Time. Location. State.
bullet
Authentication Methods
Something you know. Password or PIN. Use long passphrases.
bullet
Something you have. Smart card. Token. Mobile app.
bullet
Something you are. Fingerprint. Face. Voice. Use liveness checks.
bullet
Combine factors for MFA to raise assurance.
bullet
Use SSO to improve usability and reduce password reuse.
bullet
Account Lifecycle
Provisioning. Approval. Create accounts with minimal rights.
bullet
Maintenance. Periodic review. Password change policy. Monitor anomalies.
bullet
Deprovisioning. Disable and remove access quickly when roles change or users depart.
bullet
Authorization in Practice
Use groups and roles. Avoid direct assignment to individuals.
bullet
Apply time bound or just in time elevation for admin tasks.
bullet
Log access decisions. Review high risk approvals.
bullet
Active Recall. Test Yourself
1 Define least privilege and give one benefit.
2 Compare MAC and DAC in one sentence each.
3 List the three authentication factor types with examples.
4 What steps belong in account deprovisioning.
5 Why is role based access safer than individual grants in large environments.
Summary
Access control pairs strong identity with carefully scoped permissions. Principles reduce blast radius.
Models standardize decision making.
Use MFA and SSO for better assurance and usability. Manage the account lifecycle with timely
provisioning and removal of rights.