IT 423 MODULE SEVEN LAB: CONNECTING IOT
DEVICE TO DATABASE | 2026 UPDATE | WITH
COMPLETE SOLUTIONS SNHU.
Access control• ONLY authorized entities can use;
• ONLY those resources for which they are authorized;
• ONLY when they are allowed.
Authentication AAA OF ACCESS
CONTROL • Verification (or not) of an individual's claim (usually of identity).
• The person requesting access is the supplicant.
• The entity checking the claim is the verifier.
Authorization AAA OF ACCESS
CONTROL • An entity (via his/her/its identity) is given certain permissions to access
particular resources.
Auditing AAA OF ACCESS
CONTROL • After-the-fact analysis of data collected about an individual's activities
• Activities online can be and are monitored.
• What you know - a password for an account
• What you have - a door key, a smart card
• Who you are - fingerprint a password for an account
a door key, a smart card
you are - fingerprint
weak • Trojan horses
• MITM attacks defeat this as well
Role Based Access Control (RBAC) • Based on organizational rules
• Lessens number of opportunities for errors
Mandatory access control • Strict access control barriers to gain entry, no variation allowed.
Discretionary access control • A department can decide what access to allow for each
individual.
• Example: Edward Snowden
ISO/IEC 27002 Physical and Environmental Security
Lock Picking • It is a basic and easily learned skill.
• Requires an easily researchable understanding of how tumblers are set up inside a locking
mechanism.
DEVICE TO DATABASE | 2026 UPDATE | WITH
COMPLETE SOLUTIONS SNHU.
Access control• ONLY authorized entities can use;
• ONLY those resources for which they are authorized;
• ONLY when they are allowed.
Authentication AAA OF ACCESS
CONTROL • Verification (or not) of an individual's claim (usually of identity).
• The person requesting access is the supplicant.
• The entity checking the claim is the verifier.
Authorization AAA OF ACCESS
CONTROL • An entity (via his/her/its identity) is given certain permissions to access
particular resources.
Auditing AAA OF ACCESS
CONTROL • After-the-fact analysis of data collected about an individual's activities
• Activities online can be and are monitored.
• What you know - a password for an account
• What you have - a door key, a smart card
• Who you are - fingerprint a password for an account
a door key, a smart card
you are - fingerprint
weak • Trojan horses
• MITM attacks defeat this as well
Role Based Access Control (RBAC) • Based on organizational rules
• Lessens number of opportunities for errors
Mandatory access control • Strict access control barriers to gain entry, no variation allowed.
Discretionary access control • A department can decide what access to allow for each
individual.
• Example: Edward Snowden
ISO/IEC 27002 Physical and Environmental Security
Lock Picking • It is a basic and easily learned skill.
• Requires an easily researchable understanding of how tumblers are set up inside a locking
mechanism.