Principles for secure privileged access workstations (PAWs)
Pages
Page 1 of 10

Who is this guidance for?
This guidance helps organisations and cyber security professionals implement effective privileged access workstation (PAW) solutions in organisations. It outlines the essential characteristics of PAWs and practical considerations for implementing them in typical scenarios, in the form of principles.
Where a third party requires high-risk access to your environment, it can also help you assess whether the third party is using appropriately secured devices.
Guidance on use of PAWs in Operational Technology (OT) environments can be found in the Operational Technology guidance collection.
Why is guidance required?
Digital systems are now integral to the work of any large organisation and to work effectively, authorised staff must be able to configure, operate and maintain them. But the benefits of technology and ease of use must be balanced against the potential for compromise, which can have a significant impact on business, or even on critical national infrastructure (CNI) if the affected organisation is in a CNI sector.
Highly privileged administration interfaces are a prime target for attackers who may want to maliciously access your systems, and threat actors may try to attack the devices used to access these interfaces. Using a well-configured PAW makes this a lot more difficult.
There is no one size fits all when it comes to a PAW, or a single product to cover these controls. Implementing a PAW solution should be approached as a strategy, in line with your businesses risk tolerances.
What is a PAW?
A privileged access workstation (PAW) is a trusted physical user device that is used to protect high-risk accesses from compromise by an attacker.
A PAW aims to minimise the attack surface of the device used for high-risk accesses, making it much more difficult to compromise. At the simplest level, PAWs shouldn’t be directly exposed to high-risk functions that could directly affect the integrity of the PAW. But if access to these functions are required, including for example email services or web browsing, it should be in a careful and constrained way. A PAW should incorporate a range of robust defences to suit your organisation's needs and the threats you face.
A PAW is a physical user device, but it is just as important to consider the supporting infrastructure and the systems to which it connects, as they have an impact on its overall effectiveness and security.
Key concepts/glossary
This guidance uses generalised terms, which are defined below for this context:
The ability to influence a system by possessing the right credentials, connectivity and being present in a physical or logical location.
Highly privileged accounts and processes which bypass your normal controls and which are only used in an emergency. In this guidance, break-glass is used in the context of recovering the PAW system, not the upstream systems from which you may use a PAW to connect.
Applications used by the business to function, for example email and document collaboration services.
Where a user has no privileged roles active on their account – the expected default for the majority of users in an organisation are likely to use.
Mitigating controls designed to lessen the impact of an access being misused or compromised. This includes applying principles such as least privilege, just-enough admin or just-in-time admin.
A subset of privileged accesses which could have a critical impact on your organisation if misused or compromised. This includes actions that can change, remove or bypass security and safety controls.
Any entity that delivers services, such as network, application, infrastructure and security, via ongoing and regular management, support and active administration. This may be on a customer’s premises, in the MSP’s data centre (hosting), or in a third-party data centre.
Software and devices which are out of date and no longer supported and typically no longer receive security updates.
Where a user has the ability to perform actions that a general non-privileged user cannot, such as configuring services, modifying settings or installing programs.



