Identity and access management
Also known as IAM
The discipline of controlling who has an account, how they prove it, and what they are allowed to reach.
Identity has become the primary security perimeter. With data spread across cloud services and staff working from anywhere, the account is what an attacker is actually after, and the network boundary that used to matter no longer contains much.
Done properly it covers the whole lifecycle: provisioning when someone joins, adjusting rights when they change role, reviewing access periodically, and removing it completely when they leave. Most organizations do the first step well and the rest inconsistently.
Where this comes up
Identity and access management sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.