Identity

PAM

Privileged Access Management (PAM) protects and controls accounts that have extensive system rights.

Privileged Access Management (PAM) protects and controls accounts with extensive rights. These include domain admins, root accounts, cloud administrators, and highly privileged service accounts.

How it works

PAM stores the credentials of privileged accounts in a secure vault. Admins receive access only when needed, for a specific time, and often after approval. Passwords are automatically rotated after each use. Many solutions also record admin sessions to make them auditable later.

A practical example: An external contractor needs access to a database server for an update. They request access via the PAM system, and IT approves it for two hours. The session is recorded, and the password is automatically changed afterwards. The contractor no longer has a permanently active account.

What to look out for

  • Start with an inventory of all privileged accounts. There are often more than expected.
  • Separate administrator accounts from standard user accounts.
  • Grant permissions on a time-limited basis and only when needed (just-in-time).
  • Protect the PAM system itself carefully. It is a high-value target for attackers.
  • Include service accounts and cloud roles in your scope.

Switzerland and regulation

FINMA Circular 2023/1 expects banks and securities firms to implement special controls for privileged access. ISO 27001 also requires the restriction and monitoring of privileged rights. The Swiss federal ICT minimum standard also provides for the management of privileged access.

Relevance for the SOC

After initial compromise, attackers almost always search for administrator rights. The SOC should therefore detect any use of privileged accounts outside the PAM solution. Alerts for new members added to administrator groups are also important.

Typical mistakes

Often, PAM is introduced while direct access paths that bypass it remain open. This allows both administrators and attackers to circumvent the system.

How we implement it

In the SOC, we monitor privileged accounts and report access that bypasses the PAM system. We are happy to discuss architecture questions as part of our Security Consulting.

How ANOMAL implements this