78 terms. 37 have a diagram. Every entry has its own link.
KQUVXY
ABACAttribute-based access control
An access model that decides using attributes of the person, the resource and the context (for example department, data sensitivity, time of day) instead of only a fixed role. More flexible than RBAC, and harder to audit.
Why it matters Rules by attribute scale better than hundreds of roles, if you can still explain each decision.
A periodic check where a named reviewer confirms that each person's access is still needed. The evidence, who reviewed what and when, matters as much as the decision.
Why it matters Auditors ask for proof that access was checked, not just granted.
A credential an application presents to an API to show it may act for a user or itself. Keep it short-lived and treat it like a password while it is valid.
Why it matters It is the key to your API, so lifetime and storage matter most.
An OpenID Connect claim that says how strongly a person authenticated, using values the relying party and provider agree on. An application can ask for a higher level when an action is sensitive.
Why it matters It lets an app demand a stronger sign-in only when the action needs it.
A signed statement from the identity provider telling an application who the user is and, often, their attributes. It is the SAML counterpart of an ID token.
Why it matters It is the single signed message a SAML app trusts, so its signature check is critical.
A time-ordered record of who did what, to which resource, from where and with what result. Useful only if it is complete, protected from edits and kept long enough.
Why it matters When something goes wrong, the log is the only honest witness.
The OAuth 2.0 flow where the browser receives a one-time code and the application exchanges it for tokens over a back channel. With PKCE it is the recommended flow for web, mobile and single-page apps.
Why it matters It keeps tokens out of the browser address bar.
An emergency administrator account kept for the day normal sign-in fails. Store its credentials safely, protect it with a strong factor and alert whenever it is used.
Why it matters Without one, an outage can lock out every administrator.
A person's free, specific and informed agreement to a particular use of their data. Under the DPDP Act 2023 consent is one of the grounds for processing, and a consent record shows what was agreed and when.
Why it matters Where you rely on it, you must be able to show it.
The DPDP Act 2023 term for the organisation that decides why and how personal data is processed. An employer is usually the Data Fiduciary for employee data.
Why it matters It names who carries the duties under the Act.
DPDP ActDigital Personal Data Protection Act, 2023
India's law on the processing of digital personal data. It sets duties for Data Fiduciaries and rights for Data Principals. Check with your compliance counsel for how it applies to you.
Why it matters It sets duties for how you treat employee identity data; ask counsel how it applies.
A trust arrangement where one identity provider's sign-in is accepted by other systems or organisations, using standards such as SAML or OpenID Connect.
Why it matters It lets partners sign in without you creating more accounts.
A set of specifications from the FIDO Alliance that lets websites use public-key credentials instead of passwords. It combines the W3C WebAuthn browser API with the CTAP protocol for authenticators.
Why it matters It is the standard behind passkeys, so it works across devices and browsers.
A signed JWT issued in OpenID Connect that tells an application who just signed in, when and how. It is for the application; it is not an API credential.
Why it matters It tells the app who signed in; it is not for calling APIs.
Creating a user account in an application the first time that person signs in through SSO. Simple, but it does not remove accounts when people leave, which is what SCIM is for.
Why it matters It saves setup, but it cannot remove accounts when someone leaves.
The three moments in an identity lifecycle: someone joins, changes role or team, or leaves. Most access problems come from doing the second and third by hand.
Why it matters Most access problems happen at one of these three moments.
A JSON document, defined with RFC 7517, that publishes the public keys an identity provider uses to sign tokens. Applications fetch it to verify signatures and cache it with a sensible expiry.
Why it matters It lets apps verify tokens and follow key rotation without manual copying.
Requiring two or more kinds of proof, such as something you know, something you have and something you are. Factors differ a lot in how well they resist phishing.
Why it matters A stolen password alone should not be enough.
A random value an application sends in an OpenID Connect request and checks in the returned ID token. It ties the token to the request and blocks replay.
Why it matters It ties an ID token to the request that asked for it.
A framework for letting an application get limited access to an API on a user's behalf, or its own. It is about delegated authorization; OpenID Connect adds sign-in on top.
Why it matters It is the base layer for delegated access and for OpenID Connect.
An identity layer on top of OAuth 2.0 that gives applications a standard way to learn who signed in, using an ID token. Common for modern web and mobile applications.
Why it matters It is the modern, JSON-based way to sign people in to web and mobile apps.
A phishing-resistant credential based on WebAuthn, stored on a phone, computer or security key and unlocked with a biometric or device PIN. It replaces the password rather than adding to it.
Why it matters It removes the password, the thing attackers steal most.
An extension to the authorization code flow where the client proves it is the same one that started the request, using a one-time secret. It stops a stolen authorization code from being redeemed.
Why it matters It stops a stolen authorization code from being useful.
Issuing a new refresh token every time one is used and invalidating the old one. If an old token appears again, the server can treat it as theft and end the session.
Why it matters A stolen refresh token is noticed the moment it is reused.
A standard REST API for creating, updating and removing users and groups across systems, defined in RFC 7643 and RFC 7644. The usual way an HR system drives accounts in applications.
Why it matters It replaces CSV uploads and tickets with an automatic, standard feed.
A platform that collects logs from many systems to detect and investigate threats. Identity logs, such as sign-ins and role changes, are among the most useful inputs.
Why it matters It lets a security team see identity events beside everything else.
Signing in once to reach many applications. The identity provider authenticates you and tells each app who you are, so you do not keep separate passwords.
Why it matters Fewer passwords, one place to enforce policy and one place to switch someone off.
The W3C browser API that lets a website register and use public-key credentials held by an authenticator. The credentials are scoped to the site, which is why they resist phishing.
Why it matters It is what lets a website ask your device for a passkey.