Skip to content
BoKSA

14 Authentication, Authorisation & Accountability

Start here — Studying AAA (CyBOK KA 14)

How to use this folder. The BOKSA article gives you the map; this folder contains the actual study material. Work through the numbered documents in order — each one covers a part of the topic and points you to one or two core resources (reading, video or audio). Total self-study time for the whole topic: roughly half a day.

What you are studying

Every secure system answers three questions in order: who are you (authentication), what may you do (authorisation), what did you do (accountability). The documents in this folder:

  1. Identification, authentication factors and MFA — how systems prove who you are.
  2. Authentication in distributed systems — OAuth 2.0/OpenID Connect, SAML and Kerberos: how "Log in with..." actually works.
  3. Authorisation: models and enforcement — least privilege, RBAC/ABAC, and why "broken access control" is the number-one web risk.
  4. Accountability and logging — making actions traceable, and protecting the evidence.

The authoritative sources for the whole topic

All links in this folder were checked and working on 6 July 2026.