Privileged Access Management (PAM)

The processes and tools that control accounts with elevated rights: vaulting their credentials, granting elevation for a task, recording privileged sessions and reviewing their use.

Privileged access management is the set of processes and tools an organisation uses to control, monitor and audit accounts with elevated rights, such as administrator, root, database and service account credentials. It commonly combines several functions: a password vault that holds privileged credentials and rotates them after use; check-out with approval; just-in-time access that grants elevation only for a task; session brokering and recording, often through a jump server. The ISC2 exam outline names privileged account management under 7.4, and its lines on credential management systems (5.2) and privilege escalation (5.5) cover much of what PAM delivers.

PAM applies least privilege to the accounts where misuse does most harm. NIST SP 800-53 Rev. 5 carries the underlying requirements, including AC-2(7) on administering and monitoring privileged roles, AC-6(5) on restricting privileged accounts to defined personnel or roles, and AC-6(9) on logging privileged functions. Like any vault, a PAM platform concentrates risk, so its own administrators, sign-in and break-glass arrangements need oversight at least as strong as anything it protects. The acronym is shared with Pluggable Authentication Modules, an unrelated Unix authentication framework.

Exam relevance: a scenario is likely to describe shared administrator passwords, standing administrative rights, or no record of what administrators did. Candidates are expected to recognise PAM as the response and to name its parts: vaulting, time-bound elevation and session monitoring.