The Periodic Table is the map. The ten modules are the route.
Everything we publish on privileged access management, organised around the two things at the heart of PAM Best Practice: the Periodic Table of PAM Security, which sets out the 112 elements of a PAM programme, and the ten PAM Academy modules that teach them. Each module comes with in-depth guides and a practical exercise you can apply to your own organisation.
How it fits together
Four parts, one discipline. Start wherever you are, and follow the links between them.
Periodic Table
112 elements in seven categories: threats, risks, constraints, compliance, processes, tools and success enablers.
View the tableTen modules
Story-led lessons that follow one organisation from breach to a mature programme.
See the AcademyIn-depth guides
Free, practitioner-written guides that go deeper into each module’s topics.
Browse by moduleSelf-assessment
Ten exercises, one per module, that score your own programme against the whole table.
Get it freeThe ten-module path
Each module follows one character through a real privileged access problem. Read the related guides for depth, then complete the module’s exercise in the free self-assessment.
PAM Foundations
Why one forgotten privileged account is a business risk, the threat actors who exploit uncontrolled access, and how to read the Periodic Table.
PAM Strategy & Operating Model
Strategy before technology, who owns access decisions, joiner-mover-leaver design and the core controls.
Discovery & Assessment
Finding every privileged account, including machine and AI identities, and ranking each one by risk.
Securing Privileged Access by Risk
Tracing privileged journeys, tiering by risk, and matching vaulting, rotation, session control and just-in-time access to each journey.
Choosing a PAM Platform
How to evaluate any platform against your own requirements: testing on your own systems, integration effort and total cost.
PAM Deployment Methodologies
Choosing rollout strategies by risk, and landing change with communication, training and rollback.
Monitoring, Auditing & Incident Response
Turning privileged activity into detection, audit evidence, incident response and forensics.
Future-Proofing PAM
Cloud, DevOps, machine identities, AI agents, zero trust and the regulatory changes ahead.
Conducting a PAM Review & the Maturity Model
An audit of the whole programme across seven review levels, with every team proving its controls work.
Why PAM Projects Fail
The ten failure modes, the discipline that prevents each one, and the four access doors.
Browse by Periodic Table category
Every element has its own page. Start with a category to see its elements and where the course teaches them.
Free tools
PAM Programme Self-Assessment
The ten module exercises in one toolkit, scoring your programme against all 112 elements, with a heatmap, ranked gaps and a 90-day plan.
Get the free toolkitPeriodic Table of PAM Security
The full map of the discipline, with a page for every element.
Explore the tablePAM knowledge quiz
The PAM Practitioner Challenge: 35 questions across five levels to test what you know. A quiz about you, not an assessment of your programme.
Take the quizTeaching PAM?
The ten modules, the Periodic Table and the module exercises work as a structured unit for cyber security, computing and business courses, giving students applied practice on a real or case-study organisation. They complement your existing modules rather than replace them.
Careers in PAM
PAM Best Practice is an education provider, independent of any PAM vendor. Our guides and tools do not name, rank or recommend products.
