HLD Group
Privileged access management policy
Administrative and break-glass access controls.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 180 days · View all frameworks
1. Purpose
This policy defines the additional controls that govern privileged access — the elevated rights that can alter security configuration, reach unrelated data, or affect many systems. Privileged access is the access most sought by attackers and most damaging when misused, and so is controlled more strictly than ordinary access.
2. Scope
This policy applies to all privileged access to HLD Group systems, whether by administrators, engineers, service accounts, or third parties, and complements the Access Control Policy.
3. Definitions
- Privileged account — an account with elevated rights beyond a standard user
- Just-in-time (JIT) access — elevation granted only when needed and for a limited time
- Break-glass account — an emergency account used only when normal access is unavailable
- Privileged access management (PAM) — the tooling and process for controlling privileged access
4. Principles for privileged access
- Minimise standing privilege; prefer just-in-time, time-bound elevation
- Separate privileged accounts from day-to-day user accounts
- Require phishing-resistant MFA for all privileged access
- Log and monitor all privileged activity, and review it
- Apply the minimum scope necessary for the task (just-enough access)
5. Managing privileged access
- Privileged access is requested, approved, and time-bound through a managed process
- Sessions may be brokered, recorded, and monitored for sensitive systems
- Credentials for privileged and service accounts are vaulted and rotated
- Privileged access is recertified at least quarterly under the Access Control Policy
6. Break-glass procedures
Break-glass accounts exist for emergencies where normal access paths fail. Their credentials are tightly controlled, their use triggers alerting, and every use is reviewed promptly afterwards to confirm it was justified.
7. Framework alignment
- ISO/IEC 27001:2022 Annex A control 8.2 (privileged access rights) and 8.18 (use of privileged utility programs)
- NIST SP 800-53 Rev. 5 controls AC-2, AC-5, and AC-6
- SOC 2 Trust Services Criteria CC6.1 and CC6.3
8. Roles, exceptions, and review
The security and infrastructure functions own privileged access management under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].