Show in graph
SEC

Software → Security

IAM

The policies, processes, and systems used to manage identities and control their access to resources.

IAM

Identity and Access Management, commonly called IAM, governs who or what has an identity, how that identity is authenticated, and which resources and actions it is authorized to use.

Core responsibilities

IAM includes identity lifecycle management, roles and policies, service identities, federation, single sign-on, privileged access, access reviews, and audit trails. Good IAM applies least privilege and separates human, workload, and machine identities.

Cloud context

Cloud IAM policies often connect principals, actions, resources, and conditions. Network isolation such as a VPC does not replace IAM: network reachability and permission to perform an operation are separate controls that should reinforce each other.