Skip to main content
Guidance

Principles for secure privileged access workstations (PAWs)

How to design and securely build management devices for high-risk system maintenance and administration.

Page 3 of 10

Principle 1: Establish your organisation's PAW strategy

This principle helps you understand how a PAW complements other privileged access management approaches, and where they provide unique benefits.

To design your PAW to be an effective security control, you first need to understand how it will fit into your organisation's existing privileged access management (PAM) strategy. Each organisation is unique, with a different set of threats, risk tolerances and access requirements.

You should consider which use cases and accesses your PAW requires, and how to design it in a way that is appropriate for your wider threat context. A good understanding of the threats to your organisation, as well as your risk appetite, helps you establish which types of accesses are high risk and should be secured with a PAW.

This principle helps you understand how a PAW complements other privileged access management approaches, and where they provide unique benefits.



Published

Reviewed

Version

1.0