1.1 AAAAI Services Flashcards
AAAAI - What’s it stand for?
Authentication, authorization, auditing, accounting, identification
Identification - what is it?
Identification - The start of the security process, a subject must always provide an identity to access an object. It is how accountability is started, it’s how authentication occurs, and it’s how issues can be audited after the fact.
Authentication - what is it?
The process of verifying an identity. Requires the subject to give some info, such as a password or pin.
Authorization - what is it?
Access Control Matrix
Comparing the requested activity with the authenticated identity to determine if the user has the rights or privileges to perform said activity. This process is usually performed by an access control matrix.
Auditing - what is it?
Subjects actions are tracked and recorded. Object logs are recorded as well. This can be used to track system health and performance, as well as determining the origins of security breaches or mistakes.
Accountability - what is it?
Subjects must be held accountable for their actions, otherwise security policy is meaningless.