The Periodic Table of PAM Security
One hundred and twelve elements across seven categories, mapping the whole of privileged access: the actors who misuse it, the risks it controls, the constraints it lives inside, the standards it answers to, and the processes, tools and conditions that decide whether it holds. It started as a teaching aid and became the competency framework behind our courses.
Every element opens a page explaining why it matters, what to implement, what evidence to capture and where programmes typically go wrong.
Threat Actors
7 elements
Who misuses privileged access, and what that means for how you design controls.
Risk Factors
25 elements
Where privileged access creates exposure, and what decides how much damage a compromise can do.
PAPhysical AccessRARemote AccessICInformation ClassificationDRDisaster RecoveryPProvisioningAMAccess ManagementNDNetwork DesignCHGChange ManagementCOMTCommunication TemplatesDDeprovisioningIOTInternet of ThingsIMIdentity ManagementPMPrivileged MonitoringBEBusiness EntitlementDLDelegationJMLJoiner-Mover-LeaverCLDCloud ManagementTATraining & AwarenessPBPlaybooksCMCredential ManagementBKBackupsDIData IntegrityACLSAccess Control ListsRMRisk ManagementBIABusiness Impact Analysis
Business Constraints
6 elements
The organisational realities that shape what a programme can actually deliver.
Compliance Standards and Frameworks
14 elements
The regulations and standards that set the evidence bar for privileged access.
FISMAFederal Information Security Modernization ActISOISO StandardsGLBGramm-Leach-Bliley ActHIPAAHealth Insurance Portability and Accountability ActPCI DSSPayment Card Industry Data Security StandardCCPACalifornia Consumer Privacy ActAWS FTRAWS Foundational Technical ReviewNISNetwork and Information Systems DirectiveGDPRGeneral Data Protection RegulationMVSPMinimum Viable Secure ProductUAE NESAUAE National Electronic Security AuthorityMS COBITMicrosoft COBIT AlignmentSOXSarbanes-OxleyFEDRAMPFederal Risk and Authorization Management Program
Processes
17 elements
The repeatable routines that keep privileged access controlled after go-live.
AADAutomated DiscoveryATAsset TaggingCDChange DetectionAPRAuto Password RotationSMSession ManagementCACertificate AccessNSNetwork SegmentationFSFederated SecurityRTSReal-Time AlertsMLPMost Least PrivilegeWLPWorkload PrivilegesSCMSecure Configuration ManagementAAutomationMFAMulti-Factor AuthenticationIAMIdentity & Access ManagementSASession AuditAWApproval Workflows
Tools
34 elements
The technical capabilities a programme draws on, described without reference to any vendor.
CECompliance EfficiencyADBAudit & EvidenceSSOSingle Sign-OnCAMCloud Account ManagementPAGPrivileged Access GovernanceSIEMSIEM IntegrationSYSSyslog IntegrationARAudit & ReviewRACRole-Based Access ControlMTMobile Threat DefenceMRMonitor & ReportPCPassword ComplianceAPPApp StoreADIAnomaly Detection & IntelligenceDEVDevOps IntegrationESIEnterprise System IntegrationEAEmergency AccessPIPrivacy IntegrationPRPassword RecoveryAPIAPI IntegrationZTMZero Trust ModelBABehaviour AuthenticationNDMNetwork Device ManagementSCSupply Chain ManagementPATPatch ManagementVIVulnerability IntegrationSDISoftware Defined InfrastructureCSSCentralised Self ServicePSTDPrivileged Session Threat DetectionULLPUltra Least PrivilegeRARemote AccessAIAI IntegrationCRCredential RotationAVAudio Visual
Success Enablers
9 elements
The conditions that separate programmes that hold from those that quietly drift.
Using the table
The table is the map. The video training explains the concepts, and the implementation framework turns them into a sequence you can work through.
