← Back to PAM Best Practice main site
PAM Academy › Module 9 — Conducting a PAM Review and the PAM Maturity Model

Module 9: Conducting a PAM Review and the PAM Maturity Model

Elena audits Abby Steel across seven review levels, and each team member proves with evidence that the level they built truly works.

Story: “The Audit”
~38–40 minutes
Lead: Elena, Head of Internal Audit
PAM ReviewMaturity ModelAudit EvidenceBreak GlassDevOps
Included
Part of the PAM Best Practice Academy curriculum
Module 9 video coming soon ← Back to Module 8
  • 8-part story-led module (coming soon)
  • Follows Elena at Abby Steel
  • Practical, vendor-neutral PAM guidance
  • Key facts and real-world examples
  • 10-question knowledge check
Overview
Curriculum
Instructors
9
Module Number
8
Story Parts
40
Minutes
10
Quiz Questions
Module 9 — Conducting a PAM Review and the PAM Maturity Model
~38–40 minutes
COMING SOON
The question this module answers
How do you know, rather than believe, that your PAM programme actually works?

Eight months into the programme, Layla books Internal Audit. Elena works through seven levels of review questions, from policy and discovery to DevOps and break glass. At each level the person who built it answers with evidence, not assurances. Her verdict: 'Not a tool. Not a project. A programme.'

What you will learn
▶
Explain the five benefits of a PAM review and maturity model: enhanced security, regulatory compliance, operational efficiency, proactive risk management, and accountability and transparency.
▶
Apply the question sets for the seven review levels: Policy & Process, Asset & Account Discovery, Access Controls, Monitoring & Auditing, Technology Integration, DevOps and Break Glass.
▶
Evaluate access controls for least privilege, role creep, MFA coverage, time-bound and just-in-time access, and session management.
▶
Assess whether monitoring, training and technology integration give real, evidenced visibility of privileged activity.
▶
Review emergency (break-glass) access for approval, least privilege, monitoring, automatic termination, drills and post-incident review.
Module curriculum
1
Part 1: The Auditor
Coming soon
2
Part 2: Level 1: Policy & Process (Layla)
Coming soon
3
Part 3: Level 2: Asset & Account Discovery (Priya)
Coming soon
4
Part 4: Level 3: Access Controls (Omar)
Coming soon
5
Part 5: Level 4: Monitoring & Auditing (Amara)
Coming soon
6
Part 6: Level 5: Technology Integration (Sofia)
Coming soon
7
Part 7: Level 6: DevOps (Kenji)
Coming soon
8
Part 8: Level 7: Break Glass (Ahmed) and the Verdict
Coming soon
9
Knowledge Check10 questions · pass mark 8/10
Quiz
Part 1: The Auditor

Elena arrives with her opening line, 'Lovely roadmap. Now show me what's true today', and the five purposes a PAM review and maturity model serve.

Part 2: Level 1: Policy & Process (Layla)

Objectives, roles, approval hierarchy, least privilege, workflows, training and audit. The question is not whether a policy exists but whether it lives.

Part 3: Level 2: Asset & Account Discovery (Priya)

Inventory, discovery tools, coverage, classification, account lifecycle and ownership. Priya answers with a live dashboard updated thirty seconds ago: collect once, audit forever.

Part 4: Level 3: Access Controls (Omar)

Access rights, RBAC and role creep, dynamic privilege, MFA, time-bound and JIT access, session management and benchmarking. Omar's folder holds the evidence, including a re-tested pen test.

Part 5: Level 4: Monitoring & Auditing (Amara)

Privileged-user training and culture, automated logging, real-time alerts, SIEM integration and anomaly detection. Amara's detection metrics earn 'exemplary'.

Part 6: Level 5: Technology Integration (Sofia)

SIEM, IAM, endpoint, NAC, MFA, CMDB, incident response, vulnerability management, CASB and DLP. One legacy CMDB connector remains, and it is on track.

Part 7: Level 6: DevOps (Kenji)

Access by environment, secrets in CI/CD pipelines, tool integration and the effect on agility. Kenji shows that speed didn't drop but attack surface did.

Part 8: Level 7: Break Glass (Ahmed) and the Verdict

Emergency access conditions, approval, limits, logging, termination and drills. Ahmed, once the cautionary tale, runs them himself, and Elena delivers her verdict.

Key facts
  • Priya's discovery found 312 privileged accounts nobody knew about, plus 47 orphaned and 89 over-privileged accounts.
  • Amara's SOC: average time from anomaly to alert is under one hour, against IBM's 292-day average to identify and contain a breach involving stolen credentials. The suspicious database modification case was contained in eleven minutes.
  • Omar's evidence: MFA on 100% of privileged accounts with two documented, dated exceptions, and a pen test with three findings, all closed and re-tested by Omar himself.
  • Sofia's integration map: everything integrated except one legacy CMDB connector, due to close in six weeks.
  • Ahmed runs quarterly break-glass drills (three scenarios, two unannounced), with every account revoked automatically at the end. His last live drill was eleven days before the audit.
  • Elena's verdict: 'Not a tool. Not a project. A programme.'
Knowledge Check
Q1: Which of these is NOT one of the five purposes of a PAM review and maturity model named in Module 9?
Enhanced security
Regulatory compliance
Proactive risk management
Reducing software licence costs
Q2: At Level 1 (Policy & Process), what does Elena say the real question is?
Whether the policy is longer than competitors'
Not whether a policy exists, but whether it lives
Whether the policy was written by a consultant
Whether the policy mentions a specific vendor
Q3: Under which review level would you ask how orphaned or dormant privileged accounts are identified and managed?
Asset & Account Discovery
Technology Integration
DevOps
Break Glass
Q4: What does Elena's favourite 'role-creep' question look for?
Roles with too few permissions to do their job
Roles that have accumulated too many privileges over time
Users who have changed their passwords recently
Roles that are not yet connected to the SIEM
Q5: Why does the Level 4 (Monitoring & Auditing) review open with training questions?
Training is cheaper than monitoring
Regulators only ask about training
You cannot audit behaviour you haven't first educated
Monitoring tools require a training licence
Q6: At Level 5 (Technology Integration), what does integration with a CASB let the PAM solution do?
Monitor and control privileged access to cloud resources
Replace the need for MFA
Scan code for vulnerabilities in CI/CD pipelines
Generate employee payroll reports
Q7: What does Kenji's Level 6 (DevOps) evidence show?
DevOps was exempted from PAM to protect speed
Credential rotation remains manual in the pipeline
PAM integration slowed deployments significantly
Credential rotation is automated in CI/CD and machine identities are vaulted, and speed didn't drop but attack surface did
Q8: According to the Level 7 questions, how should least privilege be maintained even in an emergency?
Emergency accounts should hold full domain admin rights permanently
By using time-based or activity-based restrictions and predefined access levels for the type of emergency
By sharing one emergency password with the whole IT team
Least privilege is suspended during emergencies
Q9: What evidence did Ahmed present for Level 7 (Break Glass)?
A single annual tabletop exercise
A policy document awaiting approval
Quarterly drills, some unannounced, with full audit logs, automatic revocation and a post-incident review for each
A list of emergency passwords kept in a safe
Q10: Which sequence correctly lists the seven review levels in Module 9?
Policy & Process, Asset & Account Discovery, Access Controls, Monitoring & Auditing, Technology Integration, DevOps, Break Glass
Asset & Account Discovery, Policy & Process, Monitoring & Auditing, Access Controls, DevOps, Technology Integration, Break Glass
Policy & Process, Access Controls, Asset & Account Discovery, Technology Integration, Monitoring & Auditing, Break Glass, DevOps
Break Glass, DevOps, Technology Integration, Monitoring & Auditing, Access Controls, Asset & Account Discovery, Policy & Process
Requirements
Completion of Module 8 (recommended)
Basic understanding of IT administration or security concepts
Target audience: security and IT professionals, PAM practitioners and programme leads
No vendor-specific tool knowledge required — this module is vendor-neutral
Your instructors
NK
Nabeel Khaliq
IAM & Privileged Access Management SME · Founder, PAM Best Practice Ltd
Practitioner with deep hands-on experience implementing PAM across enterprise environments. Founder of PAM Best Practice Academy, a UK-registered education and community hub for PAM professionals. Arsenal and Middlesbrough fan.
AR
Adrian Russo
IAM & Privileged Access Management Architect
Senior PAM architect with extensive experience designing and deploying large-scale CyberArk and BeyondTrust implementations across enterprise environments globally. Keen cyclist.
ID
Iftikar Din
Manufacturing-focused Cyber Security Engineer
Cyber security engineer specialising in industrial and manufacturing environments. Brings real-world operational technology (OT) security perspective to PAM implementation. Middlesbrough fan who loves gardening.
Your progress
Module 9 — Conducting a PAM Review and the PAM Maturity Model
Not started0%
Module breakdown
Part 1: The AuditorComing soon
Part 2: Level 1: Policy & Process (Layla)Coming soon
Part 3: Level 2: Asset & Account Discovery (Priya)Coming soon
Part 4: Level 3: Access Controls (Omar)Coming soon
Part 5: Level 4: Monitoring & Auditing (Amara)Coming soon
Part 6: Level 5: Technology Integration (Sofia)Coming soon
Part 7: Level 6: DevOps (Kenji)Coming soon
Part 8: Level 7: Break Glass (Ahmed) and the VerdictComing soon
Knowledge Check10 questions
Up next
Module 10 — Why PAM Projects Fail
Marta, CISO of Caldwell Manufacturing, leads Module 10. Her company didn't build its programme in time, and her story shows what PAM failure actually costs.
PAM Community
Join our network of PAM practitioners, mentors and industry partners across the UK.