This ITIL core foundation video explains about access or security management process and its sub-process which is part of service design stage.
Purpose of access or security management are,
The purpose of access management is to grant access to authorised users the right to use a service, while preventing access to non-authorised users.
In practice, access management is the operational enforcement of the policies defined by information security management and availability management.
Objectives of access or security are,
To grant authorised users the right to use a service and deny access to unauthorised users
To execute policies and actions defined in security and availability management
scope of access or security are,
Access management is effectively the execution of both availability and information security management.
It enables the organisation to manage the confidentiality, integrity and availability of the organisation’s data and intellectual property.
Access management ensures users are given the right to use a service, but it does not ensure that this access is available at all agreed times – this is provided by availability management.