Glossary · OT security engineering
Privileged access management (PAM)
Also known as: PAM, Privileged account management
German: Verwaltung privilegierter Zugriffe (PAM)
In access management, privileged access management (PAM) is the set of processes and tools that control, monitor and audit the use of accounts with elevated rights, such as administrator, engineering and service accounts, including credential vaulting, just-in-time access, session recording and approval workflows.
- Security engineering
- OT security
In one sentence
Privileged access management (PAM) controls, monitors and audits accounts with elevated rights through vaulting, just-in-time access and session recording.
Example
An integrator's engineer requests access to download a PLC program; the PAM system grants it for two hours after approval, injects the credential without revealing it and records the session.
How it applies
- Engineering: In OT, privileged access includes program downloads to controllers, changes to safety parameters, firewall configuration and domain administration of SCADA servers. PAM places these actions behind approval, strong authentication and recording.
- Operation: Just-in-time access means rights exist only while needed, which applies the Principle of least privilege over time. Session recordings support investigations and show what a service partner changed.
- Maintenance: Service and machine accounts with fixed passwords are common in OT. PAM tools can rotate many of them; for devices where rotation breaks functions, document the exception and compensating measures.
- Documentation: Procedures for privileged tasks should state how access is requested and approved. Product manuals help PAM integration when they list all privileged accounts, their purposes and whether their credentials can be changed without side effects.
PAM vs. RBAC
Role-based access control (RBAC) defines which roles have which rights. PAM controls how and when the most powerful rights are actually used and makes their use traceable.