Identity Governance and Administration
Identity governance and administration, or IGA, is the discipline of deciding, granting, reviewing, and removing access to systems and data. It connects business roles and policies to the accounts, permissions, approvals, and evidence that enforce them.
itIdentity, access, and cryptography | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Identity Governance and Administration
Identity governance and administration, or IGA, is the part of access control that refuses to let a permission become a fossil. It connects a business decision to a technical grant, then keeps enough evidence to explain the grant later. That sounds bureaucratic because it is partly bureaucracy, but bureaucracy with a useful habit: it asks who owns access and when it stops.
The important distinction is between access management and governance. Access management answers whether an identity can act now. IGA asks whether it should have that access, who made that call, and whether the reason still exists. The difference is a small word, should, which has a remarkable ability to generate work.
The machinery is a control loop. A person joins, changes duties, finishes a contract, or requests elevated access. Policy and an accountable owner decide what fits. Administration changes the account, group, role, or entitlement in the target system. Evidence records the request, approval, and result. A later review checks that the permission has not wandered off to start a second career.
Two ideas keep the loop honest. A role bundles entitlements for a job or task, which makes repeated access easier to understand. A direct grant can still be necessary, but needs an owner, reason, and end condition. And least privilege means access is limited to a defined task, scope, and period. It is not a decorative label applied after the groups have multiplied.
The surprise is that a completed review is not the finish line. A reviewer can revoke access on paper while the target system keeps it. The useful question is therefore not only did someone decide, but did the account, role, or entitlement actually change? Evidence has to follow the decision all the way to the system that enforces it.
Read the Intro for the full control loop and the boundary between governance and administration. Use the Slides for the relationships among identity, owner, entitlement, target, and review. Keep the Cheatsheet nearby when comparing lifecycle events, reviews, roles, exceptions, and separation of duties. The Exercise turns the loop into a synthetic access review, where no production system receives an alarming surprise.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
Supports
- Access control, account management, identification and authentication, audit, least privilege, and separation-of-duties control concepts
- Risk-based control selection and organization-wide security and privacy control context
- https://pages.nist.gov/800-63-4/
Supports
- Digital identity, authentication, authenticator, and federation guidance
- Separation of identity proofing and authentication from authorization and governance decisions
- https://pages.nist.gov/zero-trust-architecture/VolumeB/ZeroTrustTakeaways.html
Supports
- Least privilege, policy enforcement, continuous evaluation, and resource protection concepts
- https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-53r1.pdf
Supports
- December 2006 publication of NIST SP 800-53 Revision 1 and its security-control baseline
- https://csrc.nist.gov/pubs/sp/800/53/r2/final
Supports
- December 2007 publication of NIST SP 800-53 Revision 2
- https://csrc.nist.gov/pubs/sp/800/53/r3/final
Supports
- August 2009 publication of NIST SP 800-53 Revision 3
- https://csrc.nist.gov/pubs/sp/800/53/a/r1/final
Supports
- June 2010 publication of NIST SP 800-53A Revision 1 assessment procedures
- https://csrc.nist.gov/pubs/sp/800/162/final
Supports
- January 2012 publication of NIST guidance on attribute-based access control
- https://csrc.nist.gov/pubs/sp/800/53/r4/final
Supports
- April 2013 publication of NIST SP 800-53 Revision 4
- https://csrc.nist.gov/pubs/sp/800/63/3/final
Supports
- June 2017 publication of NIST SP 800-63-3 digital identity guidelines
- https://www.nist.gov/news-events/news/2020/09/security-and-privacy-controls-information-systems-and-organizations-nist
Supports
- September 2020 publication of NIST SP 800-53 Revision 5 and integration of security and privacy controls
- https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview
Supports
- Lifecycle workflows, entitlement management, access reviews, and privileged access governance in Microsoft Entra ID Governance
- https://saviynt.com/products/identity-governance-and-administration
Supports
- Saviynt identity lifecycle, access-request, certification, and governance capabilities
- https://docs.oracle.com/en/middleware/idm/identity-governance/14.1.2/omadm/product-overview-oracle-identity-governance.html
Supports
- Oracle Identity Governance provisioning, self-service, compliance, and delegated-administration capabilities
- https://www.sailpoint.com/
Supports
- SailPoint as an identity-security and governance product option
- https://www.ibm.com/products/verify-governance
Supports
- IBM Verify Governance as an identity governance product option
- https://www.oneidentity.com/products/identity-manager/
Supports
- One Identity Manager as an identity governance and administration product option
