Cybersecurity GRC 18 items
Identity & Privileged Access Management (IAM/PAM) Audit
Audits the identity lifecycle, authentication controls, and privileged access management for administrative and service accounts across on-premises and cloud systems.
CIS v8NIST 800-53ISO 27001
Free PDF · enter your email to download.
Identity Lifecycle
- Is there a documented joiner-mover-leaver process governing account provisioning and deprovisioning? *
- Are accounts disabled or removed within a defined SLA after termination or role change? *
- Is a centralized identity provider or directory used as the authoritative source for accounts? *
- Are access rights recertified through periodic user access reviews? *
- How frequently are user access reviews performed?
Authentication Controls
- Is multi-factor authentication enforced for all remote and administrative access? *
- Is MFA enforced for externally exposed applications and cloud consoles? *
- Are password policies aligned with NIST 800-63B (length, screening against breach lists)? *
- Are phishing-resistant authenticators (FIDO2/WebAuthn) used for privileged users?
Privileged Access Management
- Are privileged accounts inventoried and separated from standard user accounts? *
- Are privileged credentials stored and rotated in a PAM vault? *
- Is just-in-time or time-bound elevation used instead of standing privileges? *
- Are privileged sessions recorded and monitored? *
- Are dedicated administrative workstations used for privileged tasks?
Service & Non-Human Accounts
- Are service accounts inventoried with a documented owner and purpose? *
- Are service account secrets rotated on a defined schedule? *
- Are default vendor accounts and passwords changed or disabled? *
- Are interactive logons for service accounts prohibited?
Download the full Identity & Privileged Access Management (IAM/PAM) Audit checklist
Get it as a clean, printable PDF — free.
