cabforum / netsec

Repository for the CA/Browser Forum Network Security Chartered Working Group
14 stars 9 forks source link

Revise use of "Account" #6

Open BenWilson-Mozilla opened 2 years ago

BenWilson-Mozilla commented 2 years ago

A data structure or access profile that contains information about a user (person, service or other entity) that provides a means to grant permissions to resources or services, apply scripts, assign profiles, and control what actions the user can perform and what they can access. Through an account, a set of credentials is created that uniquely identify and authenticate the user and that protects systems and resources from unauthorized access.

BenWilson-Mozilla commented 2 years ago

"Account" is used inconsistently when talking about "access", etc. We want the levels of access to have routine reviews, etc. E.g. 2.j. "review accounts" - however, we care about "access" not whether the "account" exists.

clintwilson commented 2 years ago
  1. Rewrite references within NSRs to consistently refer to authorization (access) and authentication.
  2. Clarify the concepts referenced (e.g. credentials, access, privileges, authn, authz)