PAM
Privileged Access Management (PAM) Checklist
A PAM checklist for admin-tiering, just-in-time access, vaulting, and standing-privilege reduction.
- Estimated time
- 6–16 Weeks
- Audience
- Identity, Infrastructure, and Security Operations Teams
- Last updated
Operational reference for privileged-access design. Supports SOC 2 and ISO 27001 evidence; not a product certification.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Discover
Phase 2: Design
Phase 3: Operate
Phase 4: Prove
FAQ
Is a PAM tool mandatory?+–
Not by name. SOC 2/ISO expect control of privileged access; tools help evidence.
What is standing privilege?+–
Always-on admin rights. JIT reduces the window an attacker can reuse.
Do SaaS admins count?+–
Yes. IdP, email, and cloud-console admins are privileged.
How often to recertify?+–
At least quarterly for the highest tiers is common auditor expectation.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer