Skip to main content
← All controls
AC-2(1) / AC-6(2) / IA-5(1) / A.9.2.3 / CIS-5.4 NIST SP 800-53 Rev 5

Privileged access management (PAM)

Demonstrate that privileged accounts are centrally managed, credentials are securely vaulted and rotated, access is granted on a time-bound and approval-based basis, and privileged sessions are monitored and recorded.

Description

What this control does

Privileged Access Management (PAM) controls the lifecycle of accounts with elevated system, application, or data permissions through dedicated tooling and processes. PAM solutions typically vault privileged credentials, enforce session recording, require just-in-time access requests with approval workflows, and rotate passwords automatically after use. This control is critical because privileged accounts represent the highest-value targets for attackers and insider threats, providing direct pathways to sensitive data, configuration changes, and system compromise.

Control objective

What auditing this proves

Demonstrate that privileged accounts are centrally managed, credentials are securely vaulted and rotated, access is granted on a time-bound and approval-based basis, and privileged sessions are monitored and recorded.

Associated risks

Risks this control addresses

  • Credential theft via phishing or malware targeting standing privileged accounts with static passwords
  • Lateral movement by attackers who compromise one privileged account and reuse credentials across multiple systems
  • Insider abuse of privileged access to exfiltrate sensitive data, manipulate financial records, or sabotage systems without detection
  • Shared administrative account usage preventing attribution of privileged actions to specific individuals during forensic investigations
  • Unmonitored privileged sessions enabling attackers to execute malicious commands or configuration changes without triggering alerts
  • Privilege escalation attacks exploiting orphaned or unmanaged privileged accounts that persist after employee departure
  • Ransomware deployment using compromised domain administrator or root credentials to encrypt enterprise-wide systems

Live threat patterns this control mitigates:

CRITICAL APT Group Runs Espionage and Crypto Fraud Operations Side by Side Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the… MEDIUM ANADOLUBANK By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Banking Volume: 0.4 GB Deadline: 2026-08-08 03:00:00 MEDIUM THY By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Aviation Volume: 4.2 GB Deadline: 2026-08-08 03:00:00 HIGH JOHNSON & JOHNSON By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Healthcare / Pharmaceutical Volume: 1.9 GB Deadline: 2026-08-08 03:00:00 MEDIUM TOGG By crpx0 Status: Leaked Location: Gebze, Turkey Sector: Automotive Volume: 1.1 GB Deadline: 2026-08-08 03:00:00 MEDIUM KUVEYT TURK By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Banking Volume: 0.8 GB Deadline: 2026-08-08 03:00:00 MEDIUM FINANSBANK By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Banking Volume: 2.3 GB Deadline: 2026-08-08 03:00:00 HIGH ASELSAN By crpx0 Status: Leaked Location: Ankara, Turkey Sector: Defense / Electronics Volume: 4.5 GB Deadline: 2026-08-08 03:00:00 MEDIUM A101 By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Grocery / Retail Volume: 0.2 GB Deadline: 2026-08-08 03:00:00 MEDIUM ANADOLU SİGORTA By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Insurance Volume: 1.2 GB Deadline: 2026-08-08 03:00:00 MEDIUM HYUNDAI By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Automotive Volume: 1.5 GB Deadline: 2026-08-08 03:00:00 MEDIUM DOĞAN HOLDİNG By crpx0 Status: Leaked Location: Istanbul, Turkey Sector: Media / Energy Conglomerate Volume: 3.1 GB Deadline: 2026-08-08 03:00:00 MEDIUM AIMS Group By the gentlemen aimsgroup.com AIMS Group LLC is a major conglomerate based in Ajman, UAE, established in 2003 with a workforce… MEDIUM Salem Saleh Babgi By the gentlemen babgi.com.sa zoominfo.com/c/salem-saleh-babgi-co-ltd/372739058 Babgi Group, founded in 1978 by Sheikh Salem Saleh Babgi, is a major Saudi Arabian conglomerate… MEDIUM Upanal CNC Solutions By the gentlemen upanalcnc.com zoominfo.com/c/upanal-cnc-solutions/370526030 Upanal CNC Solutions is an Indian company specializing in advanced metal cutting and metal forming technologies,… MEDIUM Hinduja Tech | BMW Group & Škoda Auto By global secret group Overview Country: India | Website: hindujatech.com | Revenue: $381 Million | Industry: Engineering Services, Architecture, Engineering & Design,… MEDIUM Al Hayat | Pepsi By global secret group Overview Country: Iraq | Website: alhayatco.com | Revenue: $100 Million | Industry: Food & Beverage | Employees: 501-1,000… MEDIUM Sanaa.center By black x Sanaa Center for Strategic Studies (sanaa.center) is an independent research organization focused on Yemen and the surrounding Middle… MEDIUM HİDROMEK By deadlock HİDROMEK is a leading Turkish manufacturer of heavy construction machinery recognized globally for its high-performance award-winning heavy equipment.… HIGH Bergdemo.com By settra Revenue: 42,000,000 Size: 543GB | Berg / Crushing Corporation of America: Demolition on Federal Money --- PROLOGUE In… MEDIUM Hansa Research Group Pvt. Ltd By morpheus Website: hansaresearch.com Revenue: $22 Million Hansa Research is a global, full-service market research and consumer insights agency. They… CRITICAL Ransomware Extortion Post Victim posted on a ransomware leak site after refusing or delaying ransom payment. Indicates an initial-access + privilege-escalation… HIGH India's Telegram ban hit the UAE too. Here's how to get around it India has banned Telegram until June 22 after the app was used to circulate leaked exam papers. CEO… HIGH Database Leak / Unauthorised Data Exposure Attacker dumps or sells a customer database. Implies the data store was accessible from the internet, lacked encryption… CRITICAL Ransomware Incident Confirmed ransomware encryption + extortion event. Calls for the full playbook: MFA on remote access, immutable backups, EDR… CRITICAL Initial Access Broker Sale Initial-access brokers selling administrative or remote access to a victim organisation (VPN, RDP, Exchange OWA, AWS console, AD… MEDIUM Stolen Credential Dump Aggregated credentials (often from infostealer malware) appear on criminal forums. Even if your org's data isn't in this…

Testing procedure

How an auditor verifies this control

  1. Obtain and review the current inventory of all privileged accounts across systems, applications, databases, network devices, and cloud platforms from the PAM system or identity management documentation.
  2. Verify that privileged credentials are stored in a secure password vault with encryption at rest and access logging enabled by reviewing PAM platform configuration settings.
  3. Select a sample of 10-15 privileged accounts spanning critical systems and confirm each account's password is managed by the PAM solution by attempting to retrieve credentials through the vault interface.
  4. Review access request and approval workflows by examining PAM system configuration and testing a sample access request to verify multi-level approval requirements and time-bound session grants.
  5. Examine session recording functionality by selecting 5 recent privileged sessions from logs and verifying that video recordings, keystroke logs, or command transcripts are retained and accessible.
  6. Validate automatic password rotation policies by reviewing PAM configuration for rotation frequency and examining audit logs showing successful password changes after privileged sessions.
  7. Test emergency access procedures (break-glass) by reviewing documented processes and verifying that emergency credential usage triggers immediate alerts to security teams and requires post-access justification.
  8. Analyze privileged access audit logs for the past 90 days to identify any direct logins bypassing the PAM solution, shared account usage, or violations of least-privilege principles.
Evidence required Configuration exports from the PAM platform showing vaulted accounts, password rotation policies, and approval workflows. Session recording samples (video or transcript) demonstrating monitoring capabilities. Audit logs showing access requests, approvals, credential checkouts, session durations, and password rotation events. Screenshots of the privileged account inventory with account types, systems, and last rotation dates. Break-glass access procedures and associated alert configurations.
Pass criteria All privileged accounts are inventoried and managed through a PAM solution with encrypted credential vaulting, automated password rotation at least every 90 days or after each use, approval-based access workflows, session recording or monitoring enabled, and no evidence of direct privileged access bypassing PAM controls in audit logs.

Where this control is tested

Audit programs including this control