Authentication vs. authorization, least privilege, and role-based access control for both enterprise IT and OT engineering workstations.
Identity and access management (IAM) answers two separate questions that get conflated in casual conversation: authentication ("who are you?") and authorization ("what can you do?"). This module covers multi-factor authentication, the principle of least privilege, and role-based access control (RBAC) design — plus the OT-specific wrinkle that a control-room operator often needs fast, unambiguous access during an emergency, which pulls IAM design in tension with strict least-privilege defaults.
By the end of this module you should be able to design a basic RBAC scheme for a mixed IT/OT environment and explain where a break-glass emergency-access exception belongs — a tradeoff every real facility eventually has to make explicit rather than leave ambiguous.