The document describes security concepts in WebSphere Application Server including authentication, which verifies a user's identity, authorization, which determines what resources a user can access, and single sign-on, which allows a user to access multiple systems without re-authenticating after the initial login; it also discusses how WebSphere implements security through features like global security configuration, LDAP user registries, and a security wizard to set up initial security settings.