Most credential compromises start with a stolen or phished login, not a software exploit. Follow the chain from what an identity actually is through to how an access decision gets made, and learn why some multifactor methods stop phishing and others do not.
Overview
Syllabus
Module 1
- Identity Is the New Perimeter: ICAM Foundations
- What ICAM means
- Identity versus account versus credential versus authenticator
- Human and non-person identities
- Why ICAM is foundational
- ICAM's role in Zero Trust
Module 2
- Who Are You? Identity Proofing and the Identity Lifecycle
- Proofing and enrollment
- Establishing confidence in a claimed identity
- Identity Assurance Levels
- Provisioning
- Joiner, mover, and leaver
- Authoritative sources
- Disabling, revocation, and termination
Module 3
- Prove It: Authentication and MFA Essentials
- Identification versus authentication
- The three factor types
- Single-factor versus MFA
- Multi-factor authenticators versus multiple authenticators
- Passwords, OTPs, cryptographic authenticators, and biometrics
- AAL1, AAL2, and AAL3
- Phishing-resistant authentication
Module 4
- Beyond the Password: MFA Technologies and Threats
- Authenticator apps and one-time passcodes
- Push-based authentication
- Smart cards and cryptographic credentials
- PIV credentials in federal environments
- Biometrics
- Phishing, MFA fatigue, credential theft, and adversary-in-the-middle attacks