{"id":1133,"date":"2026-09-10T07:57:55","date_gmt":"2026-09-10T07:57:55","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1133"},"modified":"2026-09-10T07:57:55","modified_gmt":"2026-09-10T07:57:55","slug":"pam","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/pam\/","title":{"rendered":"PAM"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PAM (PRIVILEGED ACCESS MANAGEMENT)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">PAM covers the small number of accounts that can change everything: root, domain admin, the production database, the cloud console, the CI\/CD deploy key. Ordinary access controls are not built for them.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Access &amp; identity<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>PAM stands for privileged access management. It is the tighter regime applied to accounts that can alter systems, read every record, or erase the audit trail. Where normal access is granted and left in place, privileged access is vaulted, requested, time-limited, recorded, and withdrawn automatically when the task ends.<\/p>\n<\/div>\n\n<p>The reason it exists is arithmetic. A standard account compromise is contained by its own permissions. A privileged account compromise is not contained by anything, which is why attackers spend most of their effort trying to reach one.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What counts as privileged<\/a><\/li>\n    <li><a href=\"#controls\">The five PAM controls<\/a><\/li>\n    <li><a href=\"#flow\">How a PAM request works<\/a><\/li>\n    <li><a href=\"#iam\">PAM and IAM are not the same<\/a><\/li>\n    <li><a href=\"#frameworks\">Where frameworks require PAM<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles PAM<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What counts as privileged<\/h2>\n\n<p>Broader than most teams assume. The human accounts are obvious and usually covered. The machine identities are the ones that get missed, and they outnumber the humans in almost every environment.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Identity<\/th><th>Why it qualifies<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Root and local administrator<\/td><td>Full control of the host, including the ability to disable logging<\/td><\/tr>\n    <tr><td>Cloud console and IAM roles<\/td><td>Can create infrastructure, alter permissions, and open network paths<\/td><\/tr>\n    <tr><td>Production database accounts<\/td><td>Direct read and write access to every customer record<\/td><\/tr>\n    <tr><td>CI\/CD and deploy credentials<\/td><td>Can push code straight to production, bypassing review<\/td><\/tr>\n    <tr><td>Service accounts and API keys<\/td><td>Standing credentials with no human owner and often no rotation schedule<\/td><\/tr>\n    <tr><td>SaaS super-admin roles<\/td><td>Can export company data or change authentication settings for everyone<\/td><\/tr>\n    <tr><td>Break-glass accounts<\/td><td>Emergency access held for outages, frequently unmonitored between uses<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"controls\" class=\"c-sage\">The five PAM controls<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Control<\/th><th>What it does<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Vaulting<\/strong><\/td><td>Credentials stored centrally and never held by an individual, so nothing lives in a password manager or a config file<\/td><\/tr>\n    <tr><td><strong>Just-in-time elevation<\/strong><\/td><td>Privilege granted for a defined window and withdrawn automatically, replacing permanent admin rights<\/td><\/tr>\n    <tr><td><strong>Approval workflow<\/strong><\/td><td>A second person authorises the elevation, creating both a control and a record of why<\/td><\/tr>\n    <tr><td><strong>Session recording<\/strong><\/td><td>What was done during the elevated window, attributable to a named person rather than a shared login<\/td><\/tr>\n    <tr><td><strong>Automatic rotation<\/strong><\/td><td>Credentials change after use or on a schedule, so an exposed secret has a short useful life<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Standing privilege is the finding<\/p>\n  <p>Auditors are less interested in whether a vault exists than in how many accounts hold permanent administrative rights. A team with three named admins who elevate on request scores better than one with a vault and twelve people carrying standing production access. Time-bound is the control. The vault is the plumbing.<\/p>\n<\/div>\n\n<h2 id=\"flow\" class=\"c-sky\">How a PAM request works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 178\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"How a privileged access request flows: request, approve, time-bound credential, recorded session, automatic revocation.\">\n  <defs><marker id=\"pamA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#2f6a89\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"28\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"76\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">1. Request<\/text>\n  <text x=\"76\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Named person,<\/text>\n  <text x=\"76\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">stated reason<\/text>\n  <line x1=\"146\" y1=\"66\" x2=\"162\" y2=\"66\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#pamA)\"\/>\n\n  <rect x=\"168\" y=\"28\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#bfd9e9\"\/>\n  <text x=\"234\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">2. Approve<\/text>\n  <text x=\"234\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Second person<\/text>\n  <text x=\"234\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">authorises<\/text>\n  <line x1=\"304\" y1=\"66\" x2=\"320\" y2=\"66\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#pamA)\"\/>\n\n  <rect x=\"326\" y=\"28\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"392\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">3. Elevate<\/text>\n  <text x=\"392\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">Credential issued<\/text>\n  <text x=\"392\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#b9c1e6\">for a fixed window<\/text>\n  <line x1=\"462\" y1=\"66\" x2=\"478\" y2=\"66\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#pamA)\"\/>\n\n  <rect x=\"484\" y=\"28\" width=\"132\" height=\"76\" rx=\"13\" fill=\"#bfd9e9\"\/>\n  <text x=\"550\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">4. Record<\/text>\n  <text x=\"550\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Session captured,<\/text>\n  <text x=\"550\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">attributed by name<\/text>\n  <line x1=\"620\" y1=\"66\" x2=\"636\" y2=\"66\" stroke=\"#2f6a89\" stroke-width=\"2\" marker-end=\"url(#pamA)\"\/>\n\n  <rect x=\"642\" y=\"28\" width=\"108\" height=\"76\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"696\" y=\"55\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">5. Revoke<\/text>\n  <text x=\"696\" y=\"75\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Window closes,<\/text>\n  <text x=\"696\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">secret rotates<\/text>\n\n  <rect x=\"10\" y=\"122\" width=\"740\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"148\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Every stage generates evidence. That record is what an auditor samples, not the tool itself.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"iam\" class=\"c-plum\">PAM and IAM are not the same<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th><\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a><\/th><th>PAM<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Population<\/td><td>Everyone with an account<\/td><td>The few accounts that can change or expose everything<\/td><\/tr>\n    <tr><td>Access model<\/td><td>Granted on joining, reviewed periodically<\/td><td>Requested per task, expires automatically<\/td><\/tr>\n    <tr><td>Default state<\/td><td>Access is held<\/td><td>Access is not held until elevated<\/td><\/tr>\n    <tr><td>Monitoring<\/td><td>Sign-in and entitlement logs<\/td><td>Full session record of actions taken<\/td><\/tr>\n    <tr><td>Failure mode<\/td><td>Entitlements accumulate quietly<\/td><td>One compromise reaches the whole estate<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>PAM sits inside IAM rather than beside it. A programme that recertifies standard users every quarter but leaves six permanent root logins untouched has an IAM process and no PAM at all.<\/p>\n\n<h2 id=\"frameworks\" class=\"c-sage\">Where frameworks require PAM<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Framework<\/th><th>What it expects<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/td><td>Restricted privileged access with approval and review evidenced across the observation window<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/td><td>An <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A control<\/a> dedicated specifically to privileged access rights<\/td><\/tr>\n    <tr><td>RBI IT Governance Directions<\/td><td>Segregation of duties, controlled administrative access, and periodic recertification for regulated entities<\/td><\/tr>\n    <tr><td>SEBI CSCRF<\/td><td>Least privilege, privileged access controls and access logging for market intermediaries<\/td><\/tr>\n    <tr><td>PCI DSS<\/td><td>Unique credentials per person, no shared accounts, and multi-factor authentication for all administrative access<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><td>Reasonable safeguards restricting who can reach personal data at scale<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Shared root logins breach nearly all of them at once, because attribution becomes impossible the moment two people use the same credential. That single change is usually the highest-value fix available to a small team.<\/p>\n\n<h2 id=\"osto\">How Osto handles PAM<\/h2>\n\n<p>Privileged access is enforced at the access gate rather than inside each individual system. Sensitive infrastructure sits behind <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> on a private domain, unreachable unless the Osto agent is present and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> has passed, which means an exposed administrative credential on its own does not open a path.<\/p>\n\n<p>Elevation events, approvals and privilege changes land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a> as endpoint and cloud activity, so an elevation followed by a new access key and an unusual data pull reads as one chain rather than three separate log lines. The resulting records map to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and Indian sectoral frameworks from one control set, feeding the wider <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> evidence base without a separate collection exercise.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Nobody should hold standing root<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto gates privileged infrastructure behind device checks and MFA, then correlates every elevation with what happened next. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Access gated at the network &middot; Evidence mapped automatically &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is PAM?<\/summary>\n  <p>Privileged access management: the controls applied to accounts capable of changing systems, reading all data, or removing audit trails. It covers vaulting credentials, granting elevation only for a fixed window, requiring approval, recording sessions and rotating secrets afterwards.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between PAM and IAM?<\/summary>\n  <p>IAM governs every account in the organisation and typically leaves access in place between reviews. PAM governs the small group of accounts that can affect everything, and assumes access is not held at all until it is requested, approved and time-limited.<\/p>\n<\/details>\n\n<details>\n  <summary>Do service accounts need PAM?<\/summary>\n  <p>Yes, and they are usually the weakest area. API keys, CI\/CD credentials and machine identities carry standing privilege with no human attached. Each needs a named owner, a rotation schedule and the same review cycle as human administrators. Auditors increasingly sample them by name.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a password vault enough?<\/summary>\n  <p>No. A vault solves storage, not standing privilege. If ten people can retrieve the root credential whenever they like, the access is still permanent and shared. The controls that change the risk are time-bound elevation, approval and attribution.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a small team need PAM?<\/summary>\n  <p>The substance, yes. The apparatus, not necessarily. Removing shared root logins, enforcing MFA on every administrative path, and keeping a record of who elevated and why will satisfy most auditors at a small company. Dedicated tooling becomes worthwhile as the number of administrators grows.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">SSO<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>PAM covers the small number of accounts that can change everything: root, domain admin, the production database, the cloud console,\u2026<\/p>\n","protected":false},"author":8,"featured_media":1134,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[535,537,536,538],"class_list":["post-1133","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-pam","tag-pam-vs-iam","tag-privileged-access-management","tag-privileged-accounts"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1133"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1133\/revisions"}],"predecessor-version":[{"id":1135,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1133\/revisions\/1135"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1134"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}