GlossarySecurity awareness

IAM

Short answer

IAM (Identity and Access Management) is the set of processes and tools that control who has access to which systems and data, from the moment someone joins a company until they leave. Its goal is that each person has exactly the access they need, and no more.

Joiners, movers and leavers

Access should follow the employee lifecycle. New joiners receive the access their role requires. When someone changes role, the access they no longer need is removed. When they leave, every account is disabled on the same day. Leftover accounts and accumulated permissions are among the most common audit findings.

Core principles

Least privilege gives each person only the access required for their job. Role based access control assigns permissions to roles rather than individuals, which makes changes easier. Privileged accounts, such as administrators, are kept separate from everyday accounts, protected with strong MFA and reviewed more often. Periodic access reviews confirm that what people have still matches what they need.

The tools

An identity provider such as Microsoft Entra ID, Google Workspace or Okta is usually the centre, with SSO connecting applications to it. A password manager covers applications that do not support SSO, and SaaS management finds the ones nobody connected. IAM is also the starting point of a Zero Trust approach.

Where it shows up in compliance

ISO 27001 covers access control, identity management, authentication information, access rights and privileged access (Annex A 5.15 to 5.18 and 8.2). The ENS, NIS2 and SOC 2 have equivalent requirements, and access reviews are among the first pieces of evidence auditors request.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub