GlossarySecurity awareness

PAM

Short answer

PAM (Privileged Access Management) is the set of controls and tools that protect accounts with elevated rights, such as administrators, service accounts and emergency access, by limiting, monitoring and recording how they are used. These accounts are the main target of attackers once inside a network.

Why privileged accounts matter

An administrator account can disable security tools, create users, access all data and deploy ransomware across the network. Attackers who get in with a normal account almost always try to obtain privileged access next.

What PAM includes

An inventory of all privileged accounts, including service accounts and those in cloud and SaaS consoles. Credentials stored in a vault and rotated automatically. Just in time access, granted for a specific task and a limited time instead of permanently. Separate administrator accounts, never used for email or browsing. Strong MFA on every privileged login, and session logging or recording for sensitive systems.

Starting without a dedicated tool

Smaller companies can cover much of the risk before buying a PAM platform: reduce the number of administrators, remove standing admin rights from laptops, use a business password manager for shared credentials, enforce MFA and review privileged access every quarter as part of IAM.

Where it shows up in compliance

ISO 27001 has a specific control for privileged access rights (Annex A 8.2), and the ENS, NIS2, SOC 2 and cyber insurers all ask how administrator access is restricted and monitored.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub