Skip to main content
Guidance

Principles for secure privileged access workstations (PAWs)

How to design and securely build management devices for high-risk system maintenance and administration.

Page 9 of 10

Principle 7: Put in place protective monitoring

When you put in place monitoring, your solution must be able to provide visibility over both the systems that support and configure the device, as well as the device itself.

PAW environments are inherently constrained by design, with a limited number of use cases. As you design how to monitor these solutions, make use of the restrictive nature so that it is easier to identify anomalous behaviours which may indicate a compromise. 

The NCSC has separate guidance principles on logging and protective monitoring as well as building a security operations centre (SOC) and you should make sure you apply these principles in a PAW environment.

When you are looking to put in place monitoring, your chosen solution must be able to provide visibility over both the systems that support and configure the device, as well as the device itself. 

Logging events should be streamed to a log-processing system in near real-time, with protections in place to prevent a threat acter tampering with logs on the device. Your log-processing system should also be well protected to prevent tampering, deletion or stopped completely.

Logs collected from the PAW solution must be immutable to make it harder for an attacker to interfere with them or to manipulate them. There may be situations where a PAW user with administrative responsibilities requires authorised privileged access to a log collection or storage solution. But this level of access should be highly restricted and, where possible, routinely audited to make sure that logs aren’t changed or amended without authorisation. Where feasible, logs for the PAW device should be sent directly to a central monitoring solution, such as your SOC.



Published

Reviewed

Version

1.0