Directory Service
What is Directory Service?
A centralized database that stores, organizes, and provides access to information about network resources and users for authentication and authorization.
Frameworks that govern directory service
What the standards actually require on directory service
Requirements naming directory service across 4 standards, quoted from the control text.
Centralize access control for all enterprise assets through a directory service or SSO provider, where supported.
CIS-6.7 · Centralize Access Control →IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.
ISM-0558 · IP phones used in public areas do not have the ability to access data networks, voicemail →Security Layer 3 Applications per X.805 Clause 7.3: The Applications Security Layer addresses requirements of network-based applications accessed by service provider customers.
X805-Layer3-Applications-Security-Email-Web-Directory-File-Transfer-E-Commerce-Video · ITU-T X.805 Security Layer 3 - Applications Security + Email + Web + Directory + File Transfer + E-Commerce + Video Conferencing + IM + Office Collaboration + SaaS + B2B EDI + Mobile Apps + APIs →This point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always cov...
nis2-directive::Art.21.2.j · Multi-factor or continuous authentication, secured communications and secured emergency communications →Questions people ask about directory service
What is Directory Service?
Why is Directory Service important for compliance?
Which compliance frameworks address Directory Service?
Where can I learn more about Directory Service?
See how Directory Service applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.