Technical security alone is no longer enough. Today, companies are expected to continuously demonstrate their cyber resilience and operational stability. At the same time, many decision-makers are losing track of what NIS2, DORA, ISO 27001 or the BSI IT-Grundschutz actually require of them. The good news: most of these requirements can be broken down into similar core principles, which organizations can address more effectively with modern identity security strategies such as Privileged Access Management (PAM).
A Basic Understanding: What Is PAM?
Before taking a closer look at regulatory obligations, would you first like to refresh your knowledge of Privileged Access Management? Then take a look at our blog post “What Is Privileged Access Management? Fundamentals and Best Practices.”
Recognize the Connection — and Use It
The burden is growing. In recent years, legislation has increasingly focused on cybersecurity — a necessary and important development in light of the rising number of attacks. For companies, however, this also means more obligations. Where IT professionals are already in short supply and time is scarce, these requirements are understandably perceived as an additional burden. What’s more, it is becoming increasingly difficult for those responsible to keep an overview. What exactly is expected of them? Where do they need to act now to avoid the risk of non-compliance?
NIS2, DORA, the BSI IT-Grundschutz and the ISO/IEC 27001 standard, which defines requirements for information security management systems, make the picture even more complex. They apply to different industries, differ in terms of legal force and each have their own areas of focus. But it helps to first identify the key aspects. Once organizations do that, several parallels become clear.
Companies are expected to manage their information security in a structured way, limit risks and be able to prove that critical systems are adequately protected. This is exactly where Privileged Access Management can come in and help address individual requirements.
NIS2: Cybersecurity as a Management Responsibility
The European Union’s NIS2 Directive, short for Network and Information Security, focuses on cybersecurity risk management, reporting obligations and accountability. It primarily affects companies in the critical infrastructure sector, but not exclusively.
The main message of the NIS2 Directive is clear: cybersecurity is not purely an IT issue, but a responsibility of corporate management. Organizations must establish appropriate technical, operational and organizational measures.
PAM approach: Access control, secure processes, multi-factor authentication and cyber hygiene are among the key building blocks of effective risk management. PAM therefore helps organizations translate general security requirements into concrete access controls.
DORA Means Digital Resilience
The Digital Operational Resilience Act, or DORA for short, is aimed primarily at financial companies and their ICT service providers. Its focus is digital operational resilience: companies should be able to detect, prevent and learn from disruptions, cyberattacks and technical failures at an early stage.
This requires clear rules for access to critical ICT systems, applications and data. Identity management, access control, logging and monitoring are considered central components of effective ICT risk management.
PAM approach: In the financial sector, admin accounts, service accounts, emergency access and third-party provider access can have far-reaching consequences. PAM helps control, document and, in the event of an incident, trace these types of access according to the need-to-know, need-to-use and least-privilege principles.
ISO 27001: Information Security with a System
Information Security Management Systems, or ISMS, help companies systematically identify, assess, treat and continuously improve information security risks. This is precisely what the internationally recognized ISO 27001 standard is designed to support.
The focus is not merely on introducing individual security measures, but on establishing a holistic management system. This includes clear responsibilities, documented processes, risk assessments, regular reviews and appropriate controls.
PAM approach: ISO 27001 requires privileged access rights to be controlled, authorized, documented and reviewed regularly. PAM translates these requirements into concrete processes and technical controls: Who is allowed to work with elevated privileges? When is this access permitted? How long does it remain active? And how is it logged?
BSI IT-Grundschutz: Keeping Permissions in View
The BSI IT-Grundschutz provides organizations with a practical methodology for systematically building and improving information security. Module ORP.4 specifically addresses identity and access rights management.
The goal is to clearly regulate access to information, applications and IT systems. This, in turn, requires clear responsibilities and permissions that are assigned as restrictively as possible.
PAM approach: Identity and access rights management is also a central aspect of the BSI IT-Grundschutz and can be implemented with modern PAM. This makes it possible to assign privileged rights based on actual need, control them and document them in a traceable manner.
Access Control at the Center
Whether EU directive, industry regulation, certification standard or national security standard, the underlying aim is always the same: to systematically identify, manage and demonstrably reduce risks — including in the context of privileged access. The relevance is clear: security incidents do not escalate simply because an account has been compromised. What matters far more is how extensive the rights associated with that account are.
For this reason, access controls have long since ceased to be a purely technical detail. They are now a central risk management issue. Companies need to know which identities are allowed to access which systems, data and applications. Access to central IT systems, cloud environments, databases, production systems, administration interfaces, and security and monitoring tools is particularly critical.
What Companies Should Review
Whether used as a guideline for assessing the current situation or as a checklist for a future PAM initiative, the following questions help those responsible evaluate the status quo and draw conclusions about necessary changes.
- Is there a complete overview of privileged accounts?
- Are admin rights permanently active or limited in time?
- Are privileged access requests approved and documented?
- Are there shared accounts?
- Are service accounts reviewed regularly?
- Is third-party provider access controlled?
- Are privileged sessions logged?
- Can access be traced in the event of an audit?
- Are there clear processes for granting, changing and revoking rights?
- Are permissions recertified regularly?
- Is emergency access available, and is it controlled?
Only then can companies turn to the question of which solution best fits their own IT environment and requirements. However, certain features should be considered minimum requirements. You can find out which ones in our blog post “Must-Haves: Six Features Modern PAM Tools Should Offer.”
Organizational Foundation: The Least-Privilege Principle
Many regulations begin with a basic organizational prerequisite: users, applications and processes should only receive the permissions they actually need to perform their tasks. One of the biggest overlaps between regulatory requirements is therefore the assignment of minimal rights. Yet this principle has still not been fully adopted in many companies.
Instead, they rely on excessive permissions that increase the risk of misuse, operating errors and unintended movement within the network. Permanent admin rights are still common in many environments, even though time-limited, task-based rights are far more aligned with today’s security requirements. Historically grown privileges make administration more difficult for IT teams.
Those responsible therefore need to clean things up. Which privileges are currently circulating within the company even though they are no longer needed? Do employees only have the rights they require for their tasks? The least-privilege principle should not be applied only to human users. Service accounts, technical users, scripts, interfaces, API keys and cloud roles with privileged access rights must also be included.
Traceability: Making Security Verifiable
Modern compliance does not end with the introduction of security measures. Companies must also show that these measures work and that they are consistently followed. This makes traceability a central component of cybersecurity.
Auditors, supervisory authorities, customers and partners no longer simply ask whether policies exist. They want to know who has access to critical systems, who approved that access, when it was used, which actions were performed and whether permissions were subsequently revoked. When it comes to privileged access in particular, trust alone is not enough.
Logs, approvals and access histories therefore become important evidence. They replace scattered Excel lists, informal agreements and shared passwords with reliable documentation. This is not only helpful during an audit, but also in the event of a security incident. If it is clearly traceable which privileged actions took place and when, incidents can be analyzed more quickly and contained in a more targeted way.
No Compliance Without PAM
NIS2, DORA, ISO 27001 and the BSI IT-Grundschutz differ in terms of target group, legal force and level of detail. However, they share several core messages. One of them is that companies must control access, limit risks and be able to prove the measures they have taken. This is precisely where PAM can help: as the link between regulatory requirements and practical IT security.
