IA-P1Govern identity scope and ownership0 of 2 milestones complete
Identity Access Modernization
List
Review milestones in a sortable hierarchy
HealthLeadPlanned finishActions
- HealthOn trackStatusIn progressLeadIdentity program ownerPlanned finishForecast finish
- HealthOn trackStatusCompleteLeadExecutive sponsorPlanned finishNot scheduledForecast finishNot scheduledIA-P1-M01Name the sponsor, program owner, and identity decision rights
- HealthOn trackStatusIn progressLeadIdentity leadPlanned finishForecast finishIA-P1-M02Define the workforce, contractor, service, and privileged identity scope
- HealthOn trackStatusPlannedLeadIdentity leadPlanned finishForecast finishIA-P1-M03Identify authoritative identity sources and account owners
- HealthOn trackStatusPlannedLeadIdentity governance leadPlanned finishForecast finishIA-P2Control identity lifecycle and operations0 of 5 milestones complete
- HealthOn trackStatusPlannedLeadIdentity operations leadPlanned finishForecast finishIA-P2-M04Define joiner, mover, and leaver handling goals
- HealthOn trackStatusPlannedLeadPlatform ownerPlanned finishForecast finishIA-P2-M10Establish service-account ownership and credential lifecycle rules
- HealthOn trackStatusPlannedLeadThird-party access ownerPlanned finishForecast finishIA-P2-M11Establish third-party identity sponsorship and expiration rules
- HealthOn trackStatusPlannedLeadAccess governance leadPlanned finishForecast finishIA-P2-M14Establish periodic access and entitlement reviews
- HealthOn trackStatusPlannedLeadProgram leadPlanned finishForecast finishIA-P2-M18Define operating metrics, review cadence, and transition to routine operations
- HealthOn trackStatusPlannedLeadIdentity security leadPlanned finishForecast finishIA-P3Protect authentication and privileged access0 of 10 milestones complete
- HealthOn trackStatusPlannedLeadPrivileged access leadPlanned finishForecast finishIA-P3-M05Establish a repeatable privileged-account inventory process
- HealthOn trackStatusPlannedLeadPrivileged access leadPlanned finishForecast finishIA-P3-M06Separate daily-use and administrative identities
- HealthOn trackStatusPlannedLeadIdentity architecture leadPlanned finishForecast finishIA-P3-M07Set authentication requirements by access risk
- HealthOn trackStatusPlannedLeadAuthentication leadPlanned finishForecast finishIA-P3-M08Establish phishing-resistant authentication for high-risk access
- HealthOn trackStatusPlannedLeadIdentity operations leadPlanned finishForecast finishIA-P3-M09Define emergency-access accounts and recovery controls
- HealthOn trackStatusPlannedLeadPrivileged access leadPlanned finishForecast finishIA-P3-M12Define a protected path for administrative access
- HealthOn trackStatusPlannedLeadPrivileged access leadPlanned finishForecast finishIA-P3-M13Establish privileged-secret rotation and revocation rules
- HealthOn trackStatusPlannedLeadSecurity operations leadPlanned finishForecast finishIA-P3-M15Centralize important authentication and privilege event logs
- HealthOn trackStatusPlannedLeadIncident response leadPlanned finishForecast finishIA-P3-M16Define identity incident triage, containment, and recovery
- HealthOn trackStatusPlannedLeadProgram leadPlanned finishForecast finishIA-P3-M17Pilot the controls with one bounded user or administrator group
Recommendations
| Actions | |||||
|---|---|---|---|---|---|
| No active recommendations for this view. | |||||
- No active recommendations for this view.



