This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Reduce Liability with a Zero Standing Privileges Approach

Download resources

About this session

Shawn McCabe, Delinea's Director of Engineering for Canada and US public sector, walks through the Gartner PAM maturity model to explain why standing privileged access remains risky even after an organization deploys a vault. He argues vaulting alone secures shared credentials well but can proliferate privileged accounts and grants 'fully armed' access once checked out, so the next maturity step, privilege elevation and delegation management (PEDM), enforces least privilege on the endpoint itself, tied to a user's own identity rather than a borrowed account. Zero standing privileges builds on that foundation by granting rights only just-in-time, for a defined window, and revoking them automatically afterward, which he ties to federal zero-trust mandates that tend to precede private-sector requirements. He recommends starting with low-risk, high-yield targets like enterprise admin and schema accounts, using the 'five whys' (who, how often, when/how long, how deep, why) to scope requests, and integrating PAM with identity governance and ITSM tools rather than treating it as standalone. An extended Q&A covers realistic adoption, approval fatigue, and the limits of software when organizational processes aren't already sound.

Key takeaways

  • Do not treat vaulting alone as complete PAM; a checked-out vault credential is often 'fully armed' with no on-host enforcement of what it can actually do.
  • Add privilege elevation and delegation management (PEDM) on endpoints so access is tied to the user's own identity, audited, and scoped to least privilege, rather than routed through a borrowed shared account.
  • Move from standing, always-on privileged group membership to just-in-time access granted for a defined window and automatically revoked afterward, to shrink the attack footprint.
  • Start zero standing privileges with low-risk, high-yield targets (enterprise admin and schema accounts, servers holding PII, domain controllers) rather than attempting full enterprise coverage at once.
  • Scope every privileged access request with the five whys: who needs it, how often, when and for how long, how deep the access goes, and what the justification is.

Speakers

Shawn Mccabe
Shawn Mccabe
Engineering Director · Delinea

Resources

Tags

More from GoSec 2023

Also from Shawn Mccabe

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.