{"id":1126,"date":"2026-09-10T06:32:45","date_gmt":"2026-09-10T06:32:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1126"},"modified":"2026-09-10T06:32:45","modified_gmt":"2026-09-10T06:32:45","slug":"iam","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/iam\/","title":{"rendered":"IAM"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: IAM (IDENTITY AND ACCESS MANAGEMENT)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">IAM is the layer that decides who exists in your systems, what each of them is allowed to touch, and what happens to that access the day someone leaves.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Access &amp; identity<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>IAM stands for identity and access management. It covers the full lifecycle of an account: creating it, authenticating it, authorising what it can reach, reviewing that entitlement periodically, and revoking it on exit. Every framework audits it, and it is the control set most likely to fail an audit through neglect rather than through a missing tool.<\/p>\n<\/div>\n\n<p>Most teams buy authentication and assume that covers IAM. Authentication proves who is asking. It says nothing about whether that person should still have production access eighteen months after moving to a different team.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#lifecycle\">The IAM lifecycle<\/a><\/li>\n    <li><a href=\"#parts\">What IAM is made of<\/a><\/li>\n    <li><a href=\"#fails\">Where IAM fails audits<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require IAM<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs IAM<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"lifecycle\">The IAM lifecycle<\/h2>\n\n<p>Four stages. Companies invest heavily in the first two and almost nothing in the last two, which is exactly the wrong distribution because the risk sits at the end.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 206\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The IAM lifecycle: provision, authenticate, authorise, review and revoke access.\">\n  <defs><marker id=\"iamA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#2f6a89\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"30\" width=\"166\" height=\"76\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"97\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6a89\">1. Provision<\/text>\n  <text x=\"97\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Account created,<\/text>\n  <text x=\"97\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">role assigned<\/text>\n  <line x1=\"184\" y1=\"68\" x2=\"202\" y2=\"68\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#iamA)\"\/>\n\n  <rect x=\"208\" y=\"30\" width=\"166\" height=\"76\" rx=\"13\" fill=\"#bfd9e9\"\/>\n  <text x=\"291\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6a89\">2. Authenticate<\/text>\n  <text x=\"291\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Prove the identity,<\/text>\n  <text x=\"291\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">every time<\/text>\n  <line x1=\"378\" y1=\"68\" x2=\"396\" y2=\"68\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#iamA)\"\/>\n\n  <rect x=\"402\" y=\"30\" width=\"166\" height=\"76\" rx=\"13\" fill=\"#bfd9e9\"\/>\n  <text x=\"485\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6a89\">3. Authorise<\/text>\n  <text x=\"485\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Grant the minimum<\/text>\n  <text x=\"485\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">needed to do the job<\/text>\n  <line x1=\"572\" y1=\"68\" x2=\"590\" y2=\"68\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#iamA)\"\/>\n\n  <rect x=\"596\" y=\"30\" width=\"150\" height=\"76\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"671\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">4. Review<\/text>\n  <text x=\"671\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">and revoke<\/text>\n  <text x=\"671\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">on change or exit<\/text>\n\n  <line x1=\"671\" y1=\"112\" x2=\"671\" y2=\"130\" stroke=\"#2f6a89\" stroke-width=\"2\"\/>\n  <line x1=\"97\" y1=\"130\" x2=\"671\" y2=\"130\" stroke=\"#2f6a89\" stroke-width=\"2\"\/>\n  <line x1=\"97\" y1=\"130\" x2=\"97\" y2=\"148\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#iamA)\"\/>\n\n  <rect x=\"14\" y=\"156\" width=\"732\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"182\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Stage 4 is the one nobody schedules. Access that is never reviewed only ever grows.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"parts\" class=\"c-sky\">What IAM is made of<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Component<\/th><th>What it does<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Directory<\/td><td>The authoritative list of who exists, usually synced from the HR system so joiners and leavers flow automatically<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">Single sign-on<\/a><\/td><td>One authentication event across many applications, which also gives you one place to switch access off<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">Multi-factor authentication<\/a><\/td><td>A second proof beyond the password, the single highest-value control in the whole set<\/td><\/tr>\n    <tr><td>Role-based access<\/td><td>Permissions attached to a job function rather than to a person, so access changes when the role does<\/td><\/tr>\n    <tr><td>Privileged access<\/td><td>Separate, tighter handling for administrator and root credentials, usually time-bound and recorded<\/td><\/tr>\n    <tr><td>Access reviews<\/td><td>A scheduled recertification where an owner confirms each entitlement is still needed, with a record either way<\/td><\/tr>\n    <tr><td>Audit logging<\/td><td>Sign-ins, privilege changes and failed attempts fed into <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the SIEM<\/a> for correlation<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"fails\" class=\"c-plum\">Where IAM fails audits<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Finding<\/th><th>What it looks like in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Orphaned accounts<\/td><td>Credentials still active weeks after an exit, usually in a tool outside the SSO directory<\/td><\/tr>\n    <tr><td>Privilege accumulation<\/td><td>Access granted for a project three roles ago and never withdrawn<\/td><\/tr>\n    <tr><td>Shared administrator credentials<\/td><td>One root login several people use, so no action can be attributed to a person<\/td><\/tr>\n    <tr><td>Unevidenced reviews<\/td><td>A review that happened in a meeting with no artefact, which an auditor records as not performed<\/td><\/tr>\n    <tr><td>Unmanaged service accounts<\/td><td>Machine identities with standing keys, no owner, and no rotation schedule<\/td><\/tr>\n    <tr><td>Shadow applications<\/td><td>Tools bought on a card, holding company data, outside the directory entirely<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Reviews need artefacts, not intentions<\/p>\n  <p>An access review that produced no record did not happen as far as an auditor is concerned. What gets sampled is the list reviewed, the person who approved it, the date, and the tickets showing what was removed. Revocations with no corresponding removal evidence are treated as open findings.<\/p>\n<\/div>\n\n<h2 id=\"frameworks\" class=\"c-sage\">Where frameworks require IAM<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Framework<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td>Logical access provisioning, modification and removal, with periodic review evidenced across the observation window<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td>Annex A controls covering identity, authentication information, access rights and privileged access<\/td><\/tr>\n    <tr><td>RBI IT Governance Directions<\/td><td>Role-based access, segregation of duties, and periodic recertification for regulated entities<\/td><\/tr>\n    <tr><td>SEBI CSCRF<\/td><td>Least privilege, privileged access controls and access logging for market intermediaries<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Reasonable security safeguards, with access restriction to personal data a core expectation<\/td><\/tr>\n    <tr><td>PCI DSS<\/td><td>Unique identifiers per user, no shared credentials, and multi-factor authentication into the cardholder environment<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>None of them prescribe a product. All of them ask the same three questions: who had access, why, and can you prove you checked.<\/p>\n\n<h2 id=\"osto\">How Osto runs IAM<\/h2>\n\n<p>Osto handles identity as part of the platform rather than as a bolt-on, which matters because access control only works when it reaches everything. Identity governs the endpoint, the cloud console, internal applications reached through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a>, and the web and API layer, so one directory decision propagates everywhere instead of stopping at whatever the SSO vendor happens to integrate with.<\/p>\n\n<p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> is enforced at the access gate rather than left to each application. Sign-ins, privilege changes and failed attempts land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as endpoint and cloud events, so an unusual login followed by a new access key reads as one incident rather than two unrelated log lines. Review cycles and revocations produce evidence automatically, mapped to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and Indian sectoral frameworks from a single control set.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">One directory, every surface<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto ties identity to endpoint, cloud, applications and the network in one platform, so access reviews are real and revocation actually reaches everywhere. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">MFA enforced at the gate &middot; Access evidence mapped automatically &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is IAM?<\/summary>\n  <p>Identity and access management: the discipline of controlling who has an account, what each account can reach, and how that access is reviewed and removed. It spans provisioning, authentication, authorisation, recertification and revocation across every system holding company data.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between authentication and authorisation?<\/summary>\n  <p>Authentication proves the identity is genuine. Authorisation decides what that identity is permitted to do once inside. A valid login with excessive permissions is an authorisation failure, not an authentication one, and it is the more common of the two.<\/p>\n<\/details>\n\n<details>\n  <summary>Is single sign-on the same as IAM?<\/summary>\n  <p>No. Single sign-on is one component. IAM also covers the directory itself, role design, privileged access, periodic review and revocation. SSO without scheduled access reviews still accumulates entitlements nobody can justify.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should access reviews run?<\/summary>\n  <p>At least quarterly for privileged and production access, and at least annually for everything else, plus an immediate review whenever someone changes role or leaves. Each cycle should produce a record showing what was reviewed, by whom, and what was removed.<\/p>\n<\/details>\n\n<details>\n  <summary>Does IAM cover service accounts?<\/summary>\n  <p>It should, and this is where most programmes are weakest. Machine identities, API keys and CI\/CD credentials need a named owner, a rotation schedule and the same review cycle as human accounts. Auditors increasingly sample them specifically.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">SSO<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>IAM is the layer that decides who exists in your systems, what each of them is allowed to touch, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":1127,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[530,532,531],"class_list":["post-1126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-iam","tag-iam-lifecycle","tag-identity-and-access-management"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1126"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1126\/revisions"}],"predecessor-version":[{"id":1128,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1126\/revisions\/1128"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1127"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}