simpl.
Cybersecurity GRC 18 items

Identity & Privileged Access Management (IAM/PAM) Audit

Audits the identity lifecycle, authentication controls, and privileged access management for administrative and service accounts across on-premises and cloud systems.

CIS v8NIST 800-53ISO 27001

Free PDF · enter your email to download.

Identity Lifecycle

  • Is there a documented joiner-mover-leaver process governing account provisioning and deprovisioning? *
  • Are accounts disabled or removed within a defined SLA after termination or role change? *
  • Is a centralized identity provider or directory used as the authoritative source for accounts? *
  • Are access rights recertified through periodic user access reviews? *
  • How frequently are user access reviews performed?

Authentication Controls

  • Is multi-factor authentication enforced for all remote and administrative access? *
  • Is MFA enforced for externally exposed applications and cloud consoles? *
  • Are password policies aligned with NIST 800-63B (length, screening against breach lists)? *
  • Are phishing-resistant authenticators (FIDO2/WebAuthn) used for privileged users?

Privileged Access Management

  • Are privileged accounts inventoried and separated from standard user accounts? *
  • Are privileged credentials stored and rotated in a PAM vault? *
  • Is just-in-time or time-bound elevation used instead of standing privileges? *
  • Are privileged sessions recorded and monitored? *
  • Are dedicated administrative workstations used for privileged tasks?

Service & Non-Human Accounts

  • Are service accounts inventoried with a documented owner and purpose? *
  • Are service account secrets rotated on a defined schedule? *
  • Are default vendor accounts and passwords changed or disabled? *
  • Are interactive logons for service accounts prohibited?

Download the full Identity & Privileged Access Management (IAM/PAM) Audit checklist

Get it as a clean, printable PDF — free.