Guidance
Principles for secure privileged access workstations (PAWs)
How to design and securely build management devices for high-risk system maintenance and administration.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 9 of 10
PAW environments are inherently constrained by design, with a limited number of use cases. As you design how to monitor these solutions, make use of the restrictive nature so that it is easier to identify anomalous behaviours which may indicate a compromise.
The NCSC has separate guidance principles on logging and protective monitoring as well as building a security operations centre (SOC) and you should make sure you apply these principles in a PAW environment.
When you are looking to put in place monitoring, your chosen solution must be able to provide visibility over both the systems that support and configure the device, as well as the device itself.
Logging events should be streamed to a log-processing system in near real-time, with protections in place to prevent a threat acter tampering with logs on the device. Your log-processing system should also be well protected to prevent tampering, deletion or stopped completely.
Logs collected from the PAW solution must be immutable to make it harder for an attacker to interfere with them or to manipulate them. There may be situations where a PAW user with administrative responsibilities requires authorised privileged access to a log collection or storage solution. But this level of access should be highly restricted and, where possible, routinely audited to make sure that logs aren’t changed or amended without authorisation. Where feasible, logs for the PAW device should be sent directly to a central monitoring solution, such as your SOC.
It’s important to be able to trust the whole of the PAW solution and putting in place monitoring helps maintain confidence in its integrity.
It’s particularly important to monitor both the configuration and change management systems. As any changes could significantly impact the security of the physical PAW device, for example by reenabling functionality or adding additional tooling, you should set up alerts when any changes are made. This allows your security team to map alterations when an authorised user makes a planned change.
Within the PAW solution, it’s important to put in place additional monitoring for all uses of privileged identity, in line with the NCSC secure systems administration guidance. Where possible, you should also put in place additional logging to monitor any actions carried out on the PAW device. This allows greater accountability of actions and is particularly important to monitor the risk of insider threat in your organisation.
As a PAW has, by its nature, a constrained set of functions, you should aim to integrate anomaly detection into device monitoring. Any activity outside of these functions is an immediate indicator of a misconfiguration or compromise. Where it’s feasible, correlate the logs between the PAW device and the target system to identify anomalies.


