Question

This week we look at authorization and authentication as a means of keeping data secure. Security...

This week we look at authorization and authentication as a means of keeping data secure. Security is, of course, essential when accessing or moving data from client side to server-side and back again. Explore the differences between authorization and authentication and the instances in which they would be appropriate to use.

When discussing with peers, look for areas in which you hold a different perspective and explain why.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Answer:

Authentication mechanism determines the user’s identity before revealing the sensitive information. It is very crucial for the system or interfaces where the user’s priority is to protect the confidential information. In the process, the user makes a provable claim about individual identity (his or her) or an entity’s identity.

The credentials or claim could be a username, password, fingerprint etc. The authentication and non-repudiation, kind of issues are handled in the application layer. The inefficient authentication mechanism could significantly affect the availability of the service.

Authorization technique is used to determine the permissions that are granted to an authenticated user. In simple words, it checks whether the user is permitted to access the particular resources or not. Authorization occurs after authentication, where the user’s identity is assured prior then the access list for the user is determined by looking up the entries stored in the tables and databases.

key differences between:

  1. The Authentication is used to verify the user’s identity in order to permit access to the system. On the other hand, the authorization determines, who should be able to access what.
  2. In the authentication process, the user credentials are verified, whereas in authorization process the authenticated user’s access list is validated.
  3. The former process is authentication, then authorization occurs.

instances in which they would be appropriate to use:

Authentication is appropriate to use where user identity, who is going to access the information, needs to be verified.

Authorization is appropriate to use where information needs to be restricted for dedicated users therefore on the basis of that permissions are granted for data access.

For Example:

Lets take the use case of Amazon Website. there are 3 type of users on Amazon Admins, Sellers, Customers.

in the first scenario, to access the website user needs to verified so that amazon could verify who is using the website information so here authentication technique is required to know their users.

In the second scenario, on the basis of user type(seller, customer and admins) some of the content should be restricted to dedicated user type like customer would only see the products which are available and listed and seller will see the service catalog and products they have listed on amazon but this information is only visible to the dedicated seller any customer could not see this information.In this scenario Authorization technique is used in order to restrict or provide particular access to the users

Add a comment
Know the answer?
Add Answer to:
This week we look at authorization and authentication as a means of keeping data secure. Security...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • REALISTIC ANSWERS PLS QUESTION: 166 A company contracts a security engineer to perform a penetration test...

    REALISTIC ANSWERS PLS QUESTION: 166 A company contracts a security engineer to perform a penetration test of its client-facing web portal. Which of the following activities would be MOST appropriate? A. Use a protocol analyzer against the site to see if data input can be replayed from the browser B. Scan the website through an interception proxy and identify areas for the code injection C. Scan the site with a port scanner to identify vulnerable services running on the web...

  • CHapter 8 from 978-0-13-408504-3 (Security in Computing 5th Edition) 1. Explain the differences between public, private,...

    CHapter 8 from 978-0-13-408504-3 (Security in Computing 5th Edition) 1. Explain the differences between public, private, and community clouds. What are some of the factors to consider when choosing which of the three to use? 2. How do cloud threats differ from traditional threats? Against what threats are cloud services typically more effective than local ones? 3. You are opening an online store in a cloud environment. What are three security controls you might use to protect customers’ credit card...

  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • FISCAL POLICY IN THEORY: March, 2020: we are on the verge of Congress and the President...

    FISCAL POLICY IN THEORY: March, 2020: we are on the verge of Congress and the President passing legislation that will empower the federal government to spend an unprecedented amount of EXTRA money not seen since World War 2 ---- in order to address the pandemic but also to help cushion the blow financially of perhaps ten or twenty million Americans --- or more --- losing their jobs, and thus suffering a drop in income. The scale of the 2020 recession...

  • Please list 5 inherent risk related items the assignment requires to list 5 inherent risks from...

    Please list 5 inherent risk related items the assignment requires to list 5 inherent risks from the description of the company that an auditor may take when deciding to accept this new client. Emphasis Heading 1 Heading 2 Heading 3 Heading 4 Description of Southwest Appliance, Inc. History and Corporate Structure Southwest Appliances, Inc. specializes in supplying a relatively small line of high-quality household appliances to residential construction contractors in a large and growing metropolitan area. Southwest has a large...

  • Help needed for Project procurement to answer Questions 1-10: Building Trust   Pauly Shore is a junior...

    Help needed for Project procurement to answer Questions 1-10: Building Trust   Pauly Shore is a junior procurement manager for the Goldwell Restaurant Group. He is responsible for the procurement of IT commodities for the data center. After months of negotiating with the three best and lowest-priced bidders for the computer paper contract, Pauly selected Frankie’s Paper Company.  Pauly’s decision was made after a round of golf at Frankie’s country club. On the eighteenth hole, Frankie extended his hand to Pauly and...

  • How can we assess whether a project is a success or a failure? This case presents...

    How can we assess whether a project is a success or a failure? This case presents two phases of a large business transformation project involving the implementation of an ERP system with the aim of creating an integrated company. The case illustrates some of the challenges associated with integration. It also presents the obstacles facing companies that undertake projects involving large information technology projects. Bombardier and Its Environment Joseph-Armand Bombardier was 15 years old when he built his first snowmobile...

  • Please read the article and answer about questions. You and the Law Business and law are...

    Please read the article and answer about questions. You and the Law Business and law are inseparable. For B-Money, the two predictably merged when he was negotiat- ing a deal for his tracks. At other times, the merger is unpredictable, like when your business faces an unexpected auto accident, product recall, or government regulation change. In either type of situation, when business owners know the law, they can better protect themselves and sometimes even avoid the problems completely. This chapter...

  • Can someone please read this case for me and answer this question and thank you. 1....

    Can someone please read this case for me and answer this question and thank you. 1. Utilize the triple bottom line to measure Uber’s performance under Kalanick’s leadership. Make sure to incorporate examples from the case in your response. Uber - A Startup’s Origins and Early Days Case: Criticizing customers. Short-changing workers. Sassing regulators. Deceiving authorities. Emphasizing rule breaking and ruthlessness in a “win at all costs” workplace culture. Is this what it takes to go from startup to a...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT