Identification
The step in which a subject claims an identity, usually by presenting a username or other unique identifier, before any proof of that claim is checked.
Identification is the claim of an identity. A user types a username, taps a badge, or presents an account number, and in doing so says “I am this subject”. NIST SP 800-63-4 describes an identifier as a value tied to one entity within a given context and never assigned to another entity in that context, which is why identifiers need to be unique. On its own, a claim establishes nothing: anyone can type someone else’s username.
Identification is commonly taught as the first of four separate functions. Authentication proves the claim, authorisation decides what the proven identity may do, and accounting records what it did. The ISC2 outline lists AAA as authentication, authorization and accounting; study sources commonly add identification at the front. The outcome of the chain is accountability, and it depends on identification being individual. A shared or generic account can be well logged, yet its records do not tie an action to one person, so accountability is weakened however good the logs are.
Exam relevance: a scenario is likely to describe one of the four steps and ask which it is. Candidates are expected to keep the claim (identification) apart from its proof (authentication), and to recognise shared accounts as a weakness in identification that undermines accountability.