--- 最後更新 : 2021/04/03 17:30 --- ###### tags: `CISSP` `D5` [TOC] # Domain 5 . Identity and Access Management (IAM) ## 5.1 Control physical and logical access to assets ### Information ### Systems ### Devices ### Facilities ## 5.2 Manage identification and authentication of people, devices, and services ### Identity management implementation ### Single/multi-factor authentication ### Accountability ### Session management ### Registration and proofing of identity ### Federated Identity Management (FIM) ### Credential management systems ## 5.3 Integrate identity as a third-party service ### On-premise ### Cloud ### Federated ## 5.4 Implement and manage authorization mechanisms ### Role Based Access Control (RBAC) ### Rule-based access control ### Mandatory Access Control (MAC) ### Discretionary Access Control (DAC) ### Attribute Based Access Control (ABAC) ## 5.5 Manage the identity and access provisioning lifecycle ### User access review ### System account access review ### Provisioning and deprovisioning ### D5 考題觀點 :::danger - Capability tables  - 身分驗證  - Kerbors   - 字典檔攻擊  - 分散式管理的缺點,無一致性的管理  - Kerbors 身分驗證  - RADIUS (與SSO無關)  - Constrained Interface 受限的介面  - Kerberos    - Ritana Sscan 視網膜掃描議題  - MAC 安全控制 ( Lattice based 基於晶格)  - RADIUS  - RADIUS 預設值  - Resource Based Access Control  - Kerbros 相關組成  - Privilege creep 範疇潛變  - LDAP 表示法  - 儲存生物資訊範本 reference template  - 密碼複雜度  - 生物辨識考量 辨識率與報名所需時間  - SAML 題組  - Q1  - Q2 架構  - Q3  - DAC 具擴展性  - SPML  - LDAP (Port 636 is the default port for LDAP-S,)  - Identity proofing 可採用雙方都知道的資訊  - OpenLDAP 密碼預設儲存使用明文  - 生物辨識的 Type 1 /Type 2 Error Type1 FRR ; FAR Type 2  - 密碼存放  - 提問類型  - AccessContrl Matrix , ACL , Capability Table  - 密碼處理  - RADIUS 保護  - OAuth 提供與雲服務驗證能力  - CAC (Common Access Card ) 是 Smart Card  - MAC 標籤 核定什麼層級,只能存取該層級  - Contentext dependtent Control (基於時間序列也是)  - Token (同步)  - Tokne (非同步)  - 生物辨識設備評估  - Simple Authentication and Security Layer , SASL (SASL 提供 LDAP 安全的驗證模式)  - OpenID  - RAID 屬於 Recovey  - RADIUS 替代方案 Diameter  - Kerberos 注意時間同步問題  - Kerberos (Kerberos, KryptoKnight, and SESAME) 都是 SSO 系統  - LDAP  :::
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up