Principles for secure privileged access workstations (PAWs)
Pages
Page 3 of 10
Principle 1: Establish your organisation's PAW strategy
To design your PAW to be an effective security control, you first need to understand how it will fit into your organisation's existing privileged access management (PAM) strategy. Each organisation is unique, with a different set of threats, risk tolerances and access requirements.
You should consider which use cases and accesses your PAW requires, and how to design it in a way that is appropriate for your wider threat context. A good understanding of the threats to your organisation, as well as your risk appetite, helps you establish which types of accesses are high risk and should be secured with a PAW.
This principle helps you understand how a PAW complements other privileged access management approaches, and where they provide unique benefits.
1.1 Understand your organisation's strategy for privileged access management
Before implementing a PAW, you first need to understand when and why you need it. Putting in place a PAW should be part of a risk-based approach which considers what could go wrong and which attacks you need to defend against.
For some privileged access use cases, an organisation may need to make choices about how to appropriately protect them. Privileged access management (PAM) is the branch of cyber security that addresses these protections and you should consider the use and implementation of PAWs as part of a wider PAM strategy.
When looking at your PAM, consider the strengths of a PAW solution, which include how it:
- minimises the attack surface – PAWs are particularly effective to protect against an external actor compromising a device
- prevents common attack vectors, such as phishing
- prevents accidental misuse of the device, such as a user of the device inadvertently installing a malicious application
- prevents lateral movement from other devices – the reason why the interactions between PAW activity and other business activity should be minimised
PAW devices can also play an important role supporting other identity and access management controls.
| Use of architectural strategies, including zero trust, doesn’t remove the need for a PAW. There are some risks that can only be mitigated with a highly trusted device. A PAW underpins your technical controls, by helping to maintain trust in them. |
1.2 Identify your high-risk accesses
PAWs can be used for all privileged accesses but it is most important to use them for high-risk accesses. An access is considered high risk if the potential impact of its compromise is serious, or if the systems which it protects could be of interest to a capable threat actor.
High-risk accesses are a subset of privileged access. A system or device is considered high risk if existing security controls can’t sufficiently mitigate its misuse. This includes accesses that can directly modify or bypass critical security controls, or expose sensitive data, and where the consequences of which could have a serious impact on your organisation. For example, an attack that targets a vital trusted component, such as a certificate server, could undermine the integrity of your systems and be very difficult to detect and recover from.
To identify which accesses are privileged or high risk, consider what a threat actor could do if they compromised that access, including what they could do with any credentials they find, or if there is connectivity to other systems, either physically or via a network. You should pay particular attention to whether it could allow an attacker to access internal systems with weak security defences, as they could be easy targets for onward attacks. The NCSC has guidance on threat modelling which can help here.
Organisations that face a heightened threat, such as those in critical national infrastructure (CNI) sectors, are likely to have systems and devices that are of interest to highly skilled threat actors. These actors may have the skills to launch further exploits after an initial compromise as part of a multi-stage attack. If this is the case for your organisation, you should apply a PAW to a wider range of privileged accesses as part of a layered defence model. Adding defence-in-depth raises the ‘cost’ for a threat actor and makes launching an attack more complex.
A PAW assumes that an authenticated user is trusted, so it doesn’t fundamentally mitigate insider threat. But using a PAW supports broader access management, monitoring and auditing controls which help mitigate insider risk. Logging and auditing controls is covered in more detail later in this guidance in principle 7.


