Security coverage

See the control, evidence and ownership behind each security domain.

Explore thirteen operational domains without turning them into thirteen disconnected products. Each pack connects outcomes to evidence, specialist roles, workflow and provider-neutral integration needs.

Domains
13
Controls
52
Workflows
52
Contracts
21

Three practical scopes

Bundle work around accountable outcomes.

Start with the service boundary that matches the decision you need to improve. Domains can be narrowed after scope and evidence are understood.

Technology, IAM and cloud platform leaders

Identity and Cloud Assurance

Reduce privilege, cloud-control and mobile-access risk with evidence that survives audit and incident response.

Identity Security and PAM · Cloud and Kubernetes Security · Mobile Device and Application Security

Discuss this scope

Engineering, product, privacy and data leaders

Product and Data Assurance

Connect secure delivery, exposure, data protection and cryptographic change to accountable release decisions.

Application and API Security · Data Security and Privacy Operations · Vulnerability and Exposure Management · Cryptographic Agility and Post-Quantum Readiness

Discuss this scope

Security operations, risk and critical-service leaders

Resilience and Operational Assurance

Prepare evidence, command paths and recoverable operating controls for incidents, suppliers and regulated services.

Digital Forensics and Malware Analysis · OT, ICS and IoT Security · Human Risk and Insider Threat · Cyber Resilience and Disaster Recovery · Threat Intelligence and External Attack Surface · NZ and Australian Compliance Operations

Discuss this scope

identity-pam · v1.0.0

Identity Security and PAM

Govern human and machine identities across their lifecycle and constrain privileged access.

NIST-CSF-PR.AACIS-5CIS-6NZISM-16

Controls and evidence

IDP-01critical

Authoritative identity lifecycle

Joiner, mover and leaver events reconcile against active accounts and access within approved timeframes.

Evidence: authoritative roster reconciliation; termination sample; exception register

Verify: Independently sample lifecycle events and confirm access removal and exception approval.

IDP-02critical

Privileged access boundary

Privileged access is vaulted or just-in-time, individually attributable and independently reviewed.

Evidence: privileged account inventory; PAM session records; break-glass test

Verify: Confirm sampled privileged sessions have approval, attribution and expiry.

IDP-03high

Access certification

Business owners periodically certify sensitive roles, groups, applications and service identities.

Evidence: certification campaign; owner decisions; revocation evidence

Verify: Reconcile approved decisions to current entitlements.

IDP-04high

Identity detection and containment

Risky sign-ins, token theft, MFA abuse and privilege changes produce owned investigations and reversible response.

Evidence: identity detection coverage; triage record; session revocation test

Verify: Run a benign identity scenario and verify alert, scope, approval and post-action state.

Accountable workflow

  1. 01

    Reconcile identities, entitlements, owners and lifecycle state.

    IAM engineer · identity reconciliation

  2. 02

    Prioritise orphaned, dormant and excessive privilege.

    identity security analyst · identity risk register

  3. 03

    Approve and execute the smallest reversible access change.

    access owner · approval and execution receipt · approval required

  4. 04

    Verify effective access and close or escalate residual risk.

    independent reviewer · post-change verification

Specialist roles

Connector capability boundary

These are integration contracts, not claims of a live vendor connection. Customer qualification must prove credentials, tenancy, rate limits, failure states and approval before use.

ContractMatching capabilityStatus
Microsoft Entra IDidentity.directory.read, identity.signin.read, identity.entitlement.read, identity.session.revoke Contract defined
Oktaidentity.directory.read, identity.signin.read, identity.session.revoke Contract defined
PAM Adapterpam.audit.read, identity.entitlement.read Contract defined
Catalog v1.0.0, pinned at revision 40ce22864666. Public metadata only; no customer evidence or credentials are included.