Architect the identity lifecycle
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- Four families behind a trustworthy account
- Resolution, validation, and verification
- Selecting the identity assurance level from impact
- What changes from IAL1 to IAL3
- Proofing types: where it happens, who attends
- Defending remote capture against injected media
- Enrollment and authenticator binding
- When proofing fails a legitimate applicant
- Choosing the durable identity join key
- Identifier scope and unwanted correlation
- Identifiers for services, processes, and devices
- Joiner, mover, and leaver events
- De-provisioning order at the termination boundary
- Reconciling desired state against target state
- What the directory tier is authoritative for
- External identities and lifecycle accountability
- Workload identity on a machine timescale
- Reading the stem: which lifecycle decision is under test
How the four identity lifecycle families are decided, delivered, and evidenced
| Question to answer | Establishing and verifying identity | Assigning identifiers | Provisioning and de-provisioning | Identity management technologies |
|---|---|---|---|---|
| What the architect decides | The assurance level and the accepted proofing paths that meet it | The durable key, its collision domain, and its reassignment rule | Which authoritative events trigger which access changes, and in what order | Which system originates each attribute, and how state is exchanged and compared |
| What drives the requirement | The harm caused by enrolling the wrong person | The systems that must correlate authorization, provisioning, and audit records | The real-world employment, contract, or sponsorship status of the subject | The number of authoritative sources and target systems that must stay consistent |
| Primary failure mode | A fraudulent or unverified enrollment that every later control then protects | A key that changes, collides, or is reassigned, breaking references and attribution | Privilege accumulation on movers and residual access after leavers | Drift between intended and actual entitlement state that nobody detects |
| What proves it works | Recorded evidence, validation and verification results, and exception rationale | Stable references across systems and unambiguous audit attribution | Access changes that track status changes within the defined risk window | Reconciliation results comparing authoritative desired state with target state |
| Where it commonly goes wrong | Accepting a valid document as proof of the presenter, or treating in-person as automatically sufficient | Using an email address as the permanent key, or recycling dormant usernames | Cloning a peer's entitlements, or deleting the identity before revoking downstream credentials | Reading a successful provisioning message as end-to-end consistency |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
References
- ISSAP Certification Exam Outline
- NIST SP 800-63-4, Digital Identity Guidelines Whitepaper
- NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment Whitepaper
- NIST SP 800-63-3, Digital Identity Guidelines (Revision 3) Whitepaper
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
- NIST SP 800-63C-4, Digital Identity Guidelines: Federation and Assertions Whitepaper
- Develop a SCIM endpoint for user provisioning to apps from Microsoft Entra ID
- What is automated app user provisioning in Microsoft Entra ID
- NIST CSRC Glossary: authoritative source
- Active Directory Domain Services overview