10.2.1.1 Uniform Access Management
52
According to Recommendation ITU-T X.1205 , the term “access management” defines
systems that may make use of both authentication and authorisation services in order to
control the use of a resource. Authentication is the process in which a user or entity
requests the establishment of an identifier to a network. On the other hand, authorisation
determines the level of allowed privileges for that entity based on access control. Access
privileges depend on the control policy definition and its enforcement. The figure below
depicts the ITU-T X.1205 reference model for secure authentication and authorisation.
Figure 19 – Secure Authentication and Authorisation reference model
In line with Reference Model, nations should obtain solutions that meet the goals below:
Centralised Authentication – The mechanism facilitates administration and removes
the need for local or host-based storage of credentials (passwords or certificates);
Centralised Authorisation – In common with authentication, this approach ensures
that access to system resources is managed in a transparent and auditable way;
Enforcement of strong (complex) passwords rules for all passwords;
Secure storage of all passwords in a one-way encrypted (hashed) format;
Simplicity – The principle focuses on enabling ease of use and administration; and
Secure logging of all events with respect to authentication and authorisation.
10.2.1.2 Secure Communications
This principle recognises the convergence of voice, data and video packets on unified
networks. Thus, countries should ensure that the technical solutions provide the different
packets types the protection appropriate to their security needs. In addition, appropriately
strong cryptographic ciphers should secure data, voice and mobile networks.
52
Obtain a copy of Recommendation ITU-T X.1205 at: http://www.itu.int/rec/T-REC-X.1205-200804-I
56