Authentication, Authorization and Accounting (AAA)
Three separate access functions: authentication proves identity, authorisation decides what that identity may do, and accounting records what it actually did.
Authentication, authorization and accounting (AAA) names three core access functions. The ISC2 exam outline lists AAA under 5.2, giving multi-factor and password-less authentication as examples. Authentication proves that a subject is who it claims to be. Authorisation decides what that authenticated subject may do. Accounting records what it did, when and from where, so that use can be reviewed, billed or investigated. Study sources commonly add identification at the front and name accountability as the result.
The three functions are separate. A system can authenticate strongly and still authorise badly, and a system that logs everything provides little accountability if accounts are shared. The term is also used for centralised protocols that carry these functions between network devices and a central server. RADIUS runs over UDP and returns authorisation inside the authentication response. TACACS+ runs over TCP and handles the three as separate exchanges, which commonly suits device administration and per-command authorisation. Diameter is commonly described as the successor to RADIUS.
Exam relevance: a scenario is likely to describe one of the three functions and ask which it is, or to ask which protocol fits a requirement. Candidates are expected to match logging to accounting, permission decisions to authorisation, and to know that TACACS+ separates the three while RADIUS combines authentication and authorisation.