Zero Trust Engineering — Privileged and just-in-time access
securityv1/01 Views
/02 About
Identity and access engineering reference for privileged and just-in-time access, including policy, logical interfaces, recovery and assurance.
Purpose: Privileged and just-in-time access. Domain: Identity and access. Family: lifecycle. Scenario trigger: Request elevated privileged action. Input assurance: Privileged task purpose, actor identity and device trust. Evaluation: Verify temporal need, approval and separation of duties. Governing policy: Just-in-time grant duration and privileged command policy. Resource-side obligation: Issue task-scoped elevation and revoke after completion. Protected concern: Administrative control interface. Logical interface: Elevation request reviewer bound privilege interval command and termination. Evidence: Privilege grant use expiration and review evidence. Failure: Standing privilege escalation or orphaned privileged session. Required recovery: Terminate elevation and independently review privileged activity. Architectural invariant: Privilege duration and scope must be minimal and monitored Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.
Curated · other · unspecified · Published by Lattix · 29 elements · 34 relationships · validated on publish
/03 Contents
- Capability
- Identity and access, Privileged and just-in-time access
- Role
- Identity and access owner
- Business Actor
- Lifecycle or resource administrator
- Activity
- Request elevated privileged action, Verify: Privileged task purpose, actor identity and device trust, Assess: Verify temporal need, approval and separation of duties, Execute: Issue task-scoped elevation and revoke after completion, Exception: Standing privilege escalation or orphaned privileged session, Recover: Terminate elevation and independently review privileged activity
- Application Component
- Privileged task purpose, actor identity and device trust, Verify temporal need, approval and separation of duties, Issue task-scoped elevation and revoke after completion
- Application
- Administrative control interface
- Policy
- Just-in-time grant duration and privileged command policy
- API
- Privileged and just-in-time access logical interface
- Message/Event Schema
- Elevation request reviewer bound privilege interval command and termination
- Data Store
- Privilege grant use expiration and review evidence
- Control
- Privileged and just-in-time access enforcement assurance
- Risk
- Standing privilege escalation or orphaned privileged session risk
- Requirement
- Privilege duration and scope must be minimal and monitored
- Measure
- Privileged and just-in-time access assurance completeness
- Trust Boundary
- Privileged and just-in-time access authority boundary
- State
- Transition verified, Lifecycle transition rejected, Baseline state established, Change pending independent validation, Transition suspended, Lifecycle transition closed