← CISSP: security, risk, and operations
05 / 10 · 30 MIN

Identity, sessions, and privileges

Manage access from onboarding through effective revocation.

Concept and mechanism

Authentication demonstrates control of authenticators; authorization determines what the identity may do. Two knowledge elements, such as password and secret question, do not create independent factor categories. MFA also does not automatically imply phishing resistance: a manually entered OTP can be relayed. Choose mechanisms meeting the required property and handle account recovery and authenticator enrollment with equal care. In federation, validate issuer, signature, validity, and audience. An authentic assertion intended for another application should not be accepted merely because email matches. Trust must match the defined recipient and context.

Guided application

Review the full access lifecycle. Disabling an IdP account may not end local sessions or issued automation tokens. When an employee leaves, identify remaining paths, revoke personal access, and move needed automation to an owned service identity. Do not presume abuse without evidence, but confirm revocation works. Apply separation of duties when policy requires independent approval; two accounts controlled by one person do not create that independence. AI agents are also nonhuman identities: limit accessible tools and data rather than inheriting all operator privileges. For temporary support, grant resource- and time-scoped privilege with approval and records. An unowned account needs investigation and controlled treatment to reduce risk without interrupting unknown dependencies.

IN PRACTICE

The offboarding ticket is closed but a personal token still deploys: the criterion is effective revocation, not only central-account disablement.

Common pitfalls

Two screens treated as two factors; OTP treated as universal resistance; signature without audience; disabled account treated as termination of every session.

Related topics: Assessment, testing, and evidence limits · Operations, incidents, and recovery

Take this idea with you

Controlled access requires appropriate identity, proportionate scope, and demonstrable revocation.

Create account

Reference: Authentication and Authenticator Management · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29