Name the sponsor, program owner, and identity decision rights
Govern identity scope and ownership
Complete · Not recorded1 person-day
Define the workforce, contractor, service, and privileged identity scope
Govern identity scope and ownership
3 person-daysCritical
Identify authoritative identity sources and account owners
Govern identity scope and ownership
3 person-daysCritical
Define joiner, mover, and leaver handling goals
Control identity lifecycle and operations
3 person-days
Establish a repeatable privileged-account inventory process
Protect authentication and privileged access
3 person-days
Separate daily-use and administrative identities
Protect authentication and privileged access
2 person-days
Set authentication requirements by access risk
Protect authentication and privileged access
3 person-daysCritical
Establish phishing-resistant authentication for high-risk access
Protect authentication and privileged access
3 person-days
Define emergency-access accounts and recovery controls
Protect authentication and privileged access
2 person-days
Establish service-account ownership and credential lifecycle rules
Control identity lifecycle and operations
3 person-days
Establish third-party identity sponsorship and expiration rules
Control identity lifecycle and operations
2 person-days
Define a protected path for administrative access
Protect authentication and privileged access
3 person-daysCritical
Establish privileged-secret rotation and revocation rules
Protect authentication and privileged access
3 person-daysCritical
Establish periodic access and entitlement reviews
Control identity lifecycle and operations
4 person-days
Centralize important authentication and privilege event logs
Protect authentication and privileged access
3 person-days
Define identity incident triage, containment, and recovery
Protect authentication and privileged access
3 person-days
Pilot the controls with one bounded user or administrator group
Protect authentication and privileged access
4 person-daysCritical
Define operating metrics, review cadence, and transition to routine operations
Control identity lifecycle and operations
2 person-daysCritical