December 2021
Beginner
550 pages
20h 48m
English
Once you define authorization rules in an authorization policy, you can enforce the rules. Each time a user requests access to a resource, the access controls either grant or deny access based on the authorization policy.
The first step in enforcing an authorization policy is to determine the identity of the subject, which is a process called identification. This process allows a subject, which can be a user, a process, or some other entity, to claim to be a specific identity. Several methods are commonly used to identify subjects, and the chosen method depends on the security requirements and capabilities of the computing environment. The next section covers various methods and guidelines for how a ...