Identity and Credential Management
Identity and credential management refers to the policies, programs, and technologies used to create, secure, and eventually retire the digital identities and credentials that people and systems use to access resources. An identity is the enduring description of a user or entity within a system, such as a name, employee number, or role, while a credential is the movable evidence, such as a password or token, presented to prove that identity when access is requested. Together these practices help organizations control who or what may access systems and information.
Identity and credential management is a domain of policies, programs, and technologies concerned with the lifecycle management of digital identities and the credentials associated with them, for both human users and non-human identities. It encompasses the creation and maintenance of identities (typically enduring attributes such as name, identifier, and role) and the creation, securing, and retirement of credentials (the evidence presented at each authentication event). In practice it is often described as a component of the broader Identity, Credential, and Access Management (ICAM) framework, which also addresses authentication, authorization, privileges, and secure access to resources across systems and platforms. As a distinct concept, identity and credential management should not be conflated with access management or authorization decisions themselves, which govern what an authenticated identity is permitted to do. Its scope, implementation, and applicable requirements vary by organization, sector, and jurisdiction.
Why it matters
For records and information governance professionals, identity and credential management underpins the trustworthiness of the access controls that protect records throughout their lifecycle. The authenticity and integrity of a record depend in part on being able to establish who created, modified, or accessed it, and on preventing unauthorized parties from doing so. Where identities are poorly managed or credentials are weakly secured, the evidential value of records may be undermined, since it becomes harder to demonstrate reliably that a record was handled only by authorized individuals or systems.
Because identity and credential management often forms part of the broader Identity, Credential, and Access Management (ICAM) framework, it is closely tied to organizational cybersecurity and to the secure access of resources across existing and emerging systems. Effective management of the identity and credential lifecycle, from creation through securing to retirement, helps reduce the risk that dormant accounts or unretired credentials remain available for misuse. This is relevant not only to human users but also to non-human identities, such as service accounts and automated processes, which may also require access to records and information.
The specific obligations surrounding identity and credential management vary by organization, sector, and jurisdiction. Depending on applicable requirements, organizations may need to demonstrate that access to sensitive or regulated records is appropriately controlled and auditable. As a matter of scope, identity and credential management concerns establishing and proving identity rather than determining what an authenticated identity is permitted to do; the latter falls to access management and authorization, which are distinct concerns.
Who it's relevant to
Inside ICM
Common questions
Answers to the questions practitioners most commonly ask about ICM.