EmpowerID IGA Core Flashcards
What is EmpowerID
A modular software product available as SaaS for on-premise installation that provides broad capabilities in Identity Governance and Administration, Access Management and Single Sign-On and Privileged Access Management
Identity Governance and Administration
A discipline that focus on identity life cycle management and access control from an administrative perspective
Privileged Account Management
focusing on special control for risky high-level access. Privileged Account Mangement (PAM) is a mechanism for getting those special accounts under control
Access Management and Single Sign On
Controlling the ability for end-users to access systems at runtime. Access Management verifies a user’s credentials and allows them access. Access Mangement also includes federation, which is the ability to access other systems after only logging in once to your identify provider
Account
Used to control permissions within the application and for authentication In EmpowerID the user account object is the Person and Stored in the Person table
Non-Person Accounts
Any account not specifically assigned to a person, such as accounts used for devices services and servers
Entitlement Management
Cataloging and managing all the accesses an account may have
Protected Resources
A system, a process, a service an information object or even a physical location that is subject to access control as defined by the owner of the resource and by other stakeholders such as a business process owner or Risk manager
Account Store Identity Entry (ASIE)
The actual live representation of an object in an external system modified by EmpowerID. The ASIE is the implementation of the CRUD methods and the attributes that are specific to that Security Boundary Type and object type in that system.
Group
Groups are the primary mechanism to grant permissions to actions
Person
Person is the user object for the EmpowerID application
Core Identity
optional object that relates multiple Person objects owned by the same human or thing
Entitlement Management
Cataloging and managing all the accesses an account may have
Protected Resources
A system, a process, a service an information object or even a physical location that is subject to access control as defined by the owner of the resource and by other stakeholders such as a business process owner or Risk manager
Resource System Type
the definition of the connector inventory data from an external system