Identity Management
Identity management is the set of policies, processes, and technologies an organization uses to keep track of who its users are and what they are allowed to access. When someone tries to log in, the system checks their credentials against a record of individuals who are authorized to have access. It is closely related to, and often described together with, access management under the broader label of identity and access management (IAM).
Identity management (IdM) refers to the administration of individual digital identities within a defined domain such as a company, network, or system, and is typically treated as part of a broader identity and access management (IAM or IdAM) framework of policies and technologies intended to ensure that the appropriate users have appropriate access to resources. Operationally, it generally involves maintaining an authoritative identity repository (an ongoing record of individuals who should have access) against which authentication attempts are validated, alongside the processes organizations use to manage and secure digital identities and control user access. In a governance, risk, and compliance context, identity and access governance is a recognized area of professional certification and program discipline; the specific controls, framework elements, and technologies applied vary by organization, sector, and jurisdiction, and this entry does not prescribe any single mandatory standard.
Why it matters
Identity management sits at the foundation of information security and access governance because it determines who can enter an organization's systems and what they can do once inside. Without a reliable, authoritative record of authorized individuals, an organization cannot consistently enforce access decisions, and the risk of unauthorized access to sensitive data and systems generally rises. In a governance, risk, and compliance context, weaknesses in identity management can undermine the control environment that boards and assurance functions rely upon.
Identity and access governance is a recognized area of professional discipline and certification, reflecting its importance to how organizations manage access-related risk and demonstrate control over their systems. The specific controls, framework elements, and technologies an organization adopts will vary by organization, sector, and jurisdiction, and no single mandatory standard applies universally. Accountability for identity management typically involves collaboration among the functions that own the underlying systems, the security or IT teams that operate the controls, and the assurance functions that provide independent evaluation of control design and operating effectiveness.
Because this entry is educational and not legal, audit, or compliance advice, organizations should evaluate their own identity management arrangements against the requirements applicable to their circumstances and the judgment of qualified professionals. Whether a given control is a legal requirement or a voluntary practice depends on the applicable law, listing rules, sector regulation, and frameworks in force.
Who it's relevant to
Inside IdM
Common questions
Answers to the questions practitioners most commonly ask about IdM.