IAM (Identity and Access Management)

What Is IAM?

IAM stands for "Identity and Access Management." It refers to the information security and business framework for ensuring that "the right individuals access the right resources, for the right reasons, the correct number of times." A similar term, "IdM" (Identity Management), is also used, and in practice these terms are often used interchangeably without clear distinction.

What Is ID (Identification)?

In the context of IAM, "ID" (Identity) refers to the set of personal attribute information created and managed on a computer system. It most often refers to "personal information belonging to individuals within a company who are authorized to access internal resources, as well as the management of that information."

  • Individuals within a company typically have attributes such as the following:
  • Name
  • Email address
  • Phone number
  • Address (office address)
  • Company affiliation
  • Department
  • Job title
  • A unique identifier such as an employee ID number
  • Information about accessible resources, etc.

What Does IAM Cover?

The scope of IAM can be classified into the following four categories.

1. Identity Management

Identity management involves managing and operating the "identity information" described above. The following explains identity management using an example within a company.

(1) Creating an Identity
When a new employee joins the company, information provided by the employee, information obtained from official documents such as a driver's license or passport, or information assigned at the time of hire is registered in the company's "HR master" database or a directory such as "Active Directory."

(2) Managing an Identity
When changes occur to registered information, the information is updated accordingly. Examples include a "department transfer," "change of phone number," or "change of job title."

(3) Deleting an Identity
Identity information is deleted when an employee leaves the company or transfers outside the scope of management (for example, a transfer from the Japanese entity to an overseas entity).

2. Access Management

This refers to the management of access rights granted when an identity is created. For example, when someone is assigned to the sales department, they are granted access to the "customer database" and "sales database," as well as permission to use "CRM" and "SFA" tools. Because identity management and access management are so closely intertwined, the term IAM combines both concepts into a single abbreviation.

Access management also includes management of access logs. From the moment a new identity is created and first accessed, until the identity is deleted and access no longer occurs, access is continuously tracked, and access logs are generated and maintained.

If access rights are not managed properly, individuals who no longer have valid access rights may still be able to access internal resources or use business systems, which in the worst case could lead to information leaks or data destruction. Access rights must therefore be revoked immediately once they are no longer needed. Note that in cases such as a "transfer" or "change of job title," the identity remains but access rights are revoked, whereas in the case of "leaving the company," both the identity itself and its access rights are removed.

3. Services

This refers to the systems and services used to manage identities. Some systems can only be viewed and operated by administrators, while others are on-demand systems that allow users to update their own information. In particular, as more companies now allow access to internal resources from smartphones, there is a growing need for services that can manage a wide range of devices beyond just computers.

4. Federation

This refers to a mechanism in which separate systems that have established a trust relationship exchange identity information using a common protocol, allowing one system to be authenticated by the other. The most well-known example is federation between directories, particularly "ADFS (Active Directory Federation Services)", which enables federation between Active Directory instances or with other directory services.

In its narrow sense, the term "federation" generally refers to "federation between directories." In its broader sense, however, the term can also include identity integration across multiple services using SAML (Security Assertion Markup Language).

What Elements Are Required in an IAM System?

Authentication

A mechanism that uses information such as passwords, SMS codes, physical devices, or biometrics to authenticate access to a system or service (in other words, a login authentication mechanism)

Authorization

A mechanism within a system or service whereby a user with different privileges authorizes an action — for example, "a general employee can only submit a purchase request, while a manager or higher-level position can approve requests submitted by general employees"

Role

A mechanism for defining the extent of privileges a user has for a particular system or service — such as administrator privileges, group administrator privileges, or user privileges — by setting them as a role

Delegation

A mechanism by which a general user, for example, delegates the management rights of their own identity to a role with greater privileges than their own

Interchange

A protocol or mechanism for exchanging identity information between two different identity management domains (management systems, directories, etc.)

From IAM to IDaaS

The technical definition of IAM is as described above, but the term IAM is generally used to refer to identity management and identity integration that predate the emergence of cloud computing. In fact, much of the IAM-related information available online was created before 2010, before cloud adoption became widespread.

Now that using cloud services is a given for companies conducting business, the term IDaaS — which assumes a cloud-based environment — is increasingly used in place of IAM, which does not presuppose the cloud (strictly speaking, IDaaS is a form of service encompassed within IAM). As the expansion of cloud adoption is irreversible, the importance of the term IDaaS relative to IAM is expected to continue growing.

IAM (Identity and Access Management)

What Is IAM?

IAM stands for "Identity and Access Management." It refers to the information security and business framework for ensuring that "the right individuals access the right resources, for the right reasons, the correct number of times." A similar term, "IdM" (Identity Management), is also used, and in practice these terms are often used interchangeably without clear distinction.

What Is ID (Identification)?

In the context of IAM, "ID" (Identity) refers to the set of personal attribute information created and managed on a computer system. It most often refers to "personal information belonging to individuals within a company who are authorized to access internal resources, as well as the management of that information."

  • Individuals within a company typically have attributes such as the following:
  • Name
  • Email address
  • Phone number
  • Address (office address)
  • Company affiliation
  • Department
  • Job title
  • A unique identifier such as an employee ID number
  • Information about accessible resources, etc.

What Does IAM Cover?

The scope of IAM can be classified into the following four categories.

1. Identity Management

Identity management involves managing and operating the "identity information" described above. The following explains identity management using an example within a company.

(1) Creating an Identity
When a new employee joins the company, information provided by the employee, information obtained from official documents such as a driver's license or passport, or information assigned at the time of hire is registered in the company's "HR master" database or a directory such as "Active Directory."

(2) Managing an Identity
When changes occur to registered information, the information is updated accordingly. Examples include a "department transfer," "change of phone number," or "change of job title."

(3) Deleting an Identity
Identity information is deleted when an employee leaves the company or transfers outside the scope of management (for example, a transfer from the Japanese entity to an overseas entity).

2. Access Management

This refers to the management of access rights granted when an identity is created. For example, when someone is assigned to the sales department, they are granted access to the "customer database" and "sales database," as well as permission to use "CRM" and "SFA" tools. Because identity management and access management are so closely intertwined, the term IAM combines both concepts into a single abbreviation.

Access management also includes management of access logs. From the moment a new identity is created and first accessed, until the identity is deleted and access no longer occurs, access is continuously tracked, and access logs are generated and maintained.

If access rights are not managed properly, individuals who no longer have valid access rights may still be able to access internal resources or use business systems, which in the worst case could lead to information leaks or data destruction. Access rights must therefore be revoked immediately once they are no longer needed. Note that in cases such as a "transfer" or "change of job title," the identity remains but access rights are revoked, whereas in the case of "leaving the company," both the identity itself and its access rights are removed.

3. Services

This refers to the systems and services used to manage identities. Some systems can only be viewed and operated by administrators, while others are on-demand systems that allow users to update their own information. In particular, as more companies now allow access to internal resources from smartphones, there is a growing need for services that can manage a wide range of devices beyond just computers.

4. Federation

This refers to a mechanism in which separate systems that have established a trust relationship exchange identity information using a common protocol, allowing one system to be authenticated by the other. The most well-known example is federation between directories, particularly "ADFS (Active Directory Federation Services)", which enables federation between Active Directory instances or with other directory services.

In its narrow sense, the term "federation" generally refers to "federation between directories." In its broader sense, however, the term can also include identity integration across multiple services using SAML (Security Assertion Markup Language).

What Elements Are Required in an IAM System?

Authentication

A mechanism that uses information such as passwords, SMS codes, physical devices, or biometrics to authenticate access to a system or service (in other words, a login authentication mechanism)

Authorization

A mechanism within a system or service whereby a user with different privileges authorizes an action — for example, "a general employee can only submit a purchase request, while a manager or higher-level position can approve requests submitted by general employees"

Role

A mechanism for defining the extent of privileges a user has for a particular system or service — such as administrator privileges, group administrator privileges, or user privileges — by setting them as a role

Delegation

A mechanism by which a general user, for example, delegates the management rights of their own identity to a role with greater privileges than their own

Interchange

A protocol or mechanism for exchanging identity information between two different identity management domains (management systems, directories, etc.)

From IAM to IDaaS

The technical definition of IAM is as described above, but the term IAM is generally used to refer to identity management and identity integration that predate the emergence of cloud computing. In fact, much of the IAM-related information available online was created before 2010, before cloud adoption became widespread.

Now that using cloud services is a given for companies conducting business, the term IDaaS — which assumes a cloud-based environment — is increasingly used in place of IAM, which does not presuppose the cloud (strictly speaking, IDaaS is a form of service encompassed within IAM). As the expansion of cloud adoption is irreversible, the importance of the term IDaaS relative to IAM is expected to continue growing.