<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is maintenance in the process of identity management? in CCSP Study Group</title>
    <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47965#M114</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Considering only Identity Management as part of the IAM, it includes provisioning (identity assertions) and password management. Password management covers generation, storage and security controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we talk about permissions, that is part of RBAC, and access management. That is part of IAM, but not of the Identity Management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might be wrong. Please refer to the Official Study guide, section 7.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it may help,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Oct 2021 08:44:15 GMT</pubDate>
    <dc:creator>luisantonio</dc:creator>
    <dc:date>2021-10-19T08:44:15Z</dc:date>
    <item>
      <title>What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47706#M101</link>
      <description>&lt;P&gt;According to the question c03.046 of CCSP Official Practice Tests, t&lt;SPAN&gt;he process of identity management includes maintenance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What exactly do you think is maintenance? For example, does it include changing passwords and permissions?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:59:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47706#M101</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2023-10-09T09:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47722#M102</link>
      <description>I think IAM maintenance would mean:&lt;BR /&gt;&lt;BR /&gt;1. Removing old identities for staff who have left the company.&lt;BR /&gt;2. Updating permissions for staff who have changed positions.&lt;BR /&gt;3. Perhaps removing roles that are no longer required.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Joseph Charles-Walcott&lt;BR /&gt;&lt;BR /&gt;1(868) 685-7969</description>
      <pubDate>Sun, 03 Oct 2021 10:17:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47722#M102</guid>
      <dc:creator>JoeBuilder</dc:creator>
      <dc:date>2021-10-03T10:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47725#M103</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1426780573"&gt;@JoeBuilder&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should have given you options of the question. They are as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Provisioning&lt;/LI&gt;&lt;LI&gt;Maintenance&lt;/LI&gt;&lt;LI&gt;Deprovisioning&lt;/LI&gt;&lt;LI&gt;Redaction&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Then I have reviewed your ideas and my ones. Here are my thoughts:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;"changing permissions" and your idea #2 would be a kind of provisioning.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Your ideas, #1 and #3, would be deprovisioning.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;So I am still wondering what exactly identity maintenance activities are.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 21:50:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47725#M103</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2021-10-03T21:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47730#M104</link>
      <description>&lt;P&gt;Very good question,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1459503571"&gt;@Masahiro&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As others have pointed out,maintenace would involve reconfirming currently assigned roles, removing roles no longer held by the assignee, adding new roles then approved, and adding or changing other secondary data in the database, such as answers to challenge&amp;nbsp;questions used for forgotten password tasks. Depending on the ID database, it may also involve updating or confirming secondary contact information, assigned supervisor (needed to confirm current privileges and roles), etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 18:10:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47730#M104</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2021-10-04T18:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47743#M106</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/780103681"&gt;@CraginS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have understood as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Identities start with provisioning, continue to be maintained and end with deprovisioning. It is identity and access management lifecycle. So there are many activities in the maintenance phase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:00:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47743#M106</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2021-10-05T11:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47903#M113</link>
      <description>&lt;P&gt;I found the definition of the maintenance in the process of identity management. &lt;A href="https://www.iso.org/standard/77582.html" target="_blank" rel="noopener"&gt;ISO/IEC 24760-1:2019&lt;/A&gt; defines it as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;10 Maintenance&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;An identity management system can perform maintenance on identity information it has registered by changing one or more of the attribute values in an identity. An identity management system shall specify mechanisms for maintaining the integrity and accuracy of attributes it stores. It shall maintain the identity information stored in the register as an accurate representation of the identity. An identity information authority shall provide the most accurate data available for an identity in a process that respects privacy&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can download it from the following website for free.&lt;/P&gt;&lt;P&gt;&lt;A href="https://standards.iso.org/ittf/PubliclyAvailableStandards/index.html" target="_blank"&gt;https://standards.iso.org/ittf/PubliclyAvailableStandards/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 00:42:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47903#M113</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2021-10-16T00:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47965#M114</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Considering only Identity Management as part of the IAM, it includes provisioning (identity assertions) and password management. Password management covers generation, storage and security controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we talk about permissions, that is part of RBAC, and access management. That is part of IAM, but not of the Identity Management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might be wrong. Please refer to the Official Study guide, section 7.4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it may help,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luis.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:44:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47965#M114</guid>
      <dc:creator>luisantonio</dc:creator>
      <dc:date>2021-10-19T08:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47977#M115</link>
      <description>&lt;P&gt;In my opinion, maintenance in IAM consists of a life cycle approach - JML or Joiners, Movers, and Leavers.&amp;nbsp; Each part of the cycle includes onboarding, role change, and separation.&amp;nbsp; Each of these includes differing amounts of maintenance activities.&amp;nbsp; For example, joiners would include creation of the account, provisioning initial permissions to objects, communication to the end user, etc.&amp;nbsp; Movers would require modification in terms of add or remove permissions, revaluation of application provisioning, etc.&amp;nbsp; Leavers have maintenance of deprovisioning of all access, placing the account in a disabled state, updating reporting, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maintenance to me is a security operations function.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 01:40:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/47977#M115</guid>
      <dc:creator>AntiEvil</dc:creator>
      <dc:date>2021-10-20T01:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/48004#M118</link>
      <description>&lt;P&gt;Agree, mainly is the JML process. joiner, mover and leaver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depend how you consider (some consider the below as security compliance):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;recording and&amp;nbsp; confirming entitlement,&lt;/LI&gt;&lt;LI&gt;determining segregation of duty and&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;recertification of identity, role and access&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;may also consider as part of maintenance.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 01:44:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/48004#M118</guid>
      <dc:creator>csjohnng</dc:creator>
      <dc:date>2021-10-21T01:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: What is maintenance in the process of identity management?</title>
      <link>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/48929#M144</link>
      <description>&lt;P&gt;The part that catches my eye in *maintenance* not mentioned - is that this is not a 1 time event 3 years ago - but implies an intentional routine check-up frequency or other effort to gain comfort an automated process control design is still working effectively (i.e., does not exclude new systems, entities, directories, attributes, credentialing secret types, changed policies requirements, etc.).&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 04:11:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CCSP-Study-Group/What-is-maintenance-in-the-process-of-identity-management/m-p/48929#M144</guid>
      <dc:creator>ob1knb</dc:creator>
      <dc:date>2022-01-06T04:11:12Z</dc:date>
    </item>
  </channel>
</rss>

