This document discusses security concepts for grid computing including identity, authentication, privacy, integrity, authorization, single sign-on, and delegation. It describes how public key infrastructure (PKI) using X.509 certificates can provide identity and authentication. The Grid Security Infrastructure (GSI) allows secure access to grid resources using PKI and builds on it to enable single sign-on and delegation through the use of proxy credentials. Authorization can be done through server-side mechanisms like gridmaps or client-side authorization. Services like MyProxy act as credential repositories.