# SP-037 Privileged User Management

Status: active. Release 26.02. Modified 2026-02-13. Licence: CC BY-SA 4.0.

Scope: Comprehensive privileged access management pattern covering credential vaulting, just-in-time access, session recording, standing privilege elimination, and break-glass procedures. Addresses the full lifecycle of privileged accounts from provisioning through monitoring to decommissioning, with emphasis on reducing the attack surface created by administrative access.
Use when: This pattern applies to every organisation with systems that have administrative or root-level access -- which is every organisation. It is particularly critical for: organisations with regulatory obligations around privileged access (financial services, healthcare, government), environments where privileged access abuse could cause significant financial or operational harm (trading systems, payment systems,...
Not when: There are no contraindications for privileged access management -- the question is one of scale and sophistication.

## Controls (33, NIST SP 800-53 ids)
- Critical (8): AC-02, AC-06, AU-02, AU-12, IA-02, IA-05, SC-28, SI-04
- Important (21): AC-03, AC-05, AC-12, AC-17, AU-03, AU-06, CA-02, CA-07, CM-02, CM-03, CM-05, IA-04, IR-04, PM-12, PM-14, PS-04, PS-07, SA-04, SA-09, SC-07, SC-12
- Standard (4): CM-07, PE-03, PS-05, RA-05

## What each critical control mitigates (8)
- AC-02 Account Management: T-PUM-001, T-PUM-002, T-PUM-003, T-PUM-004, T-PUM-007, T-PUM-008, T-PUM-009, T-PUM-011
- AC-06 Least Privilege: T-PUM-002, T-PUM-003, T-PUM-009
- AU-02 Event Logging: T-PUM-007, T-PUM-008
- AU-12 Audit Record Generation: T-PUM-005, T-PUM-006
- IA-02 Identification and Authentication (Organizational Users): T-PUM-007
- IA-05 Authenticator Management: T-PUM-001, T-PUM-004, T-PUM-007, T-PUM-010, T-PUM-012
- SC-28 Protection of Information at Rest: T-PUM-001, T-PUM-010, T-PUM-012
- SI-04 System Monitoring: T-PUM-001, T-PUM-002, T-PUM-006

## Threats and the controls that mitigate them (12)
- T-PUM-001 Credential theft via pass-the-hash, Kerberoasting, or credential dumping: IA-05, AC-02, SC-28, SI-04
- T-PUM-002 Lateral movement using compromised domain admin or cloud admin credentials: AC-02, AC-06, AC-12, AC-17, SI-04
- T-PUM-003 Privilege escalation through misconfigured IAM roles or group membership: AC-06, CA-02, CM-02, AC-02
- T-PUM-004 Service account compromise enabling persistent access to critical systems: IA-05, CM-02, SA-04, AC-02
- T-PUM-005 Insider threat from privileged administrators abusing legitimate access: AC-12, AU-03, AU-12, AU-06, PM-12, AC-05
- T-PUM-006 Living-off-the-land attacks using legitimate admin tools (PowerShell, WMI): SI-04, AU-12, AC-03, CM-07
- T-PUM-007 Shared credential abuse where individual accountability cannot be established: IA-02, IA-05, AU-02, AU-03, AC-02
- T-PUM-008 Break-glass credential misuse for unauthorised access outside emergencies: AU-02, AC-02, IR-04, PM-14
- T-PUM-009 Cloud IAM privilege escalation through role chaining or policy misconfiguration: AC-02, AC-06, SA-09, CA-07
- T-PUM-010 PAM platform compromise giving adversary control of all vaulted credentials: SC-28, SC-07, IA-05, CM-03
- T-PUM-011 Orphaned privileged accounts remaining active after personnel departure: AC-02, PS-04, PS-05, IA-04
- T-PUM-012 Hardcoded credentials in source code or configuration files exposed via repository leak: IA-05, SA-04, CM-02, SC-28

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-037/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-037/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 32 KB: /api/v1/patterns/SP-037
- Page for people: /patterns/sp-037/
- Related: SP-010 Identity Management Pattern; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-032 Modern Authentication; SP-033 Passkey Authentication

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
