Principles for secure privileged access workstations (PAWs)
Pages
Page 5 of 10
Principle 3: Establish a foundation of trust
A PAW has some of the highest levels of access and permissions in your organisation, so it’s important to build a strong foundation of trust in it, both at the start and throughout its lifecycle. Not doing this could later undermine its security controls.
As part of this, it’s also crucial to consider the supply chain for all of the components, software and services used in your PAW solution. You should think about how you gain effective control and oversight when you design the PAW solution, and how to maintain it throughout its lifecycle.
You should use a ‘clean’ environment to build trust in your PAW solution. A building-block approach is best here, starting with a clean standalone initial device, before then rolling out and operating the PAWs across your organisation at scale.
Starting small helps you establish a foundation of trust on which to build.
3.1 Establish effective control and oversight of your supply chain
Establishing trust in your PAW solution starts with understanding its supply chain and the components used within it. The NCSC supply chain security guidance provides a set of principles for all stages of procurement. You should pay particular attention to:
End user devices
You should only procure devices for your PAW solution which support hardware-backed security features. This allows you to make use of the latest root of trust, confidential computing and cryptographic technologies on your PAW. The NCSC has separate guidance to help you both securely choose devices and purchase them.
Buy your devices from trusted suppliers, and use manufacturers with good supply chain security to make sure you receive authentic devices. Part of this is considering where in the supply chain the device is assigned and attributed to your organisation, as some suppliers may pass end-customer details to the manufacturer (especially if you are planning to use services such as zero-touch enrolment.) These steps make it more difficult for an attacker to target your organisation through a supply chain attack.
Software including the operating system (OS) and firmware
All software, including the OS and firmware, must originate from a trusted source. You should only use official sites or repositories to download software. To import data into your PAW network, using a file transfer mechanism helps avoids direct web access. Where possible, your import process should scan for viruses and validate the package cryptographically, to ensure that the data has not been modified before it reaches you.
Managed services and maintenance
If you are using a managed service provider (MSP) to manage your PAW solution on an ongoing basis, the MSP will have full access to all of your systems. You should only consider doing this if you can trust the MSP and are confident they have in place strong cyber defences. The NCSC has supply chain guidance that helps you manage MSP access. |
If it isn’t feasible to manage your own PAW solution in-house, it's critical that the MSP only manages your PAW from a device you trust, such as your own PAW, and that separation between your organisation and their other customers is maintained. This helps reduce the impact spreading, or ‘blast radius’, if another of their customers is compromised.
Any dependency between your PAW and the MSP infrastructure creates a new attack vector, which could allow an attacker to pivot into your network if the third party is compromised. Where possible, these dependencies should be removed to mitigate this risk.
Identity services should never be shared and all MSP users should use accounts administered by your organisation. These accounts should be managed using normal business process, including a joiners, movers and leavers (JML) process. This gives you effective oversight of the users who have management privileges of your PAW solution. This is important because if you don’t have assurance here, your technical controls could be undermined and you can’t establish trust.
The MSP should only be able to carry out the required actions to administer the PAW solution itself. Your organisation should monitor and audit all connectivity from a MSP to ensure actions are both legitimate and planned. An MSP must access the solution in a way that allows actions to be attributable to a user, and they must not use any shared access.
3.2 Implement a standalone device to build your solution
It’s essential to secure a PAW solution in the initial set-up phase. To minimise the risk of cross-contamination and maintain integrity, avoid building a PAW system using existing systems. Instead, begin with new and clean devices procured through a well-understood supply chain.
In small and single deployment scenarios, the initial device might serve as the sole PAW device. To make sure it functions effectively as a PAW, it should adhere to all necessary lockdown policy requirements. Typically, this initial device is used to provision your PAW management environment, creating a clean and physically separate segment of your network. This segment can then be expanded to include additional PAW devices and supporting services.
If your solution requires more than a single PAW device, the initial device should eventually be integrated into your PAW mobile device management (MDM) software, and enrolled as a PAW device. You can find out more about this in principle 4.
It's important not to use this standalone device for administration until all technical controls and policy lockdowns are in place. Once an MDM is configured, this initial device should be enrolled so that the policy is applied to all devices.


