Privileged Access Workstation
What is Privileged Access Workstation?
A hardened and dedicated computing environment used exclusively for performing sensitive administrative tasks, isolated from general-purpose activities and the internet.
Terms that appear alongside privileged access workstation
Each of these is named in at least one of the same controls as privileged access workstation. The number is how many controls name both.
- isolation 3 shared controls
- zero trust 2 shared controls
- secure access service edge 2 shared controls
- access control 2 shared controls
- microsegmentation 2 shared controls
- authentication 2 shared controls
Frameworks that govern privileged access workstation
What the standards actually require on privileged access workstation
Requirements naming privileged access workstation across 5 standards, quoted from the control text.
Provide secured, isolated workstations for sensitive roles such as administrators, developers and critical service operators, so administrative sessions do not originate from general-purpose endpoints.
ASBv3-PA-6 · Use privileged access workstations →Implement Operations Security + Physical/Environmental Security + Communications and Network Security per MTCS SS 584. Operations Security (ISO 27001 Annex A.12 alignment) - documented operating procedures + capacity management + separation of dev/test/prod +...
MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS · MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D...
MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering · MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering →Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...
MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation →Questions people ask about privileged access workstation
What is Privileged Access Workstation?
Why is Privileged Access Workstation important for compliance?
Which compliance frameworks address Privileged Access Workstation?
Where can I learn more about Privileged Access Workstation?
See how Privileged Access Workstation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.