Identity & Access · IA-Q03

Question

Are privileged (admin, root, service) identities inventoried, governed, and reviewed?

Why This Matters

Privileged misuse is high-impact. Governance reduces blast radius and improves forensics.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Build inventory; assign owners; schedule reviews.| |2 → 3| Deploy PAM; onboard crown jewels; record sessions.| |3 → 4| Enforce JIT; rotate secrets/keys; quarterly certifications.| |4 → 5| Add analytics/UEBA and automated containment for anomalies.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping