Page 147 - CISSO_Prep_ Guide
P. 147

The challenge of identity management has led to the
            development and implementation of several single sign-on
            solutions.



            Single Sign-on

            There are many types of single sign-on solutions, but they all
            have similar goals - to help manage system access consistently
            and measurably. A single sign-on solution is, by its nature, a
            centralized access control solution since it maintains access to
            multiple systems.


            Centralized Access Control

            Centralized access control is the principle of managing access to
            all systems and networks from a central location, or by a
            centralized department. There are many advantages to a
            centralized access control system:
               1.  Access is consistently managed; access permissions are
                   easier to monitor and review.
               2.  Access levels are enforced on all systems in the same
                   way.
               3.  For example, the same number of invalid login attempts
                   before the lockout.

            However, centralized access control systems also have
            disadvantages in that they can be inflexible, unresponsive to
            local requirements, be a single point of failure, and
            bureaucratically heavy.

            With a centralized system, all access requests must be submitted
            to a central department, which then sets up, or removes, the
   142   143   144   145   146   147   148   149   150   151   152