Privileged Access Management (PAM)
Privileged access management (PAM) is protecting your most sensitive credentials - the keys to the kingdom by keeping them secure and closely governed. A privileged few should be allowed access to the most sensitive accounts (PAM), systems and data. Protiviti can assess, implement, optimise, manage privilege access to reduce risk.
Features
- Development of PAM program -policies, Risk model, training
- Privileged account discovery and risk assessment.
- Health check of PAM tool install to ensure proper foundation.
- Development of strategy and roadmap to mature PAM program.
- Plan strategic and tactical approach to roll out PAM tool,
- PAM solution technical design and architecture.
- PAM tool installation, upgrade, and optimisation
- Remediation and onboarding of PAM accounts.
- Communications, training and procedures for new PAM accounts
- Managed services offering for ongoing management of PAM tool
Benefits
- Identify, detect and document privileged accounts
- Secure storage and management of privilege credentials
- Enhanced PAM controls with session management and recording
- No password exposure with the vault for password less access
- Strategise, lead and maintain PAM infrastructure
- Governance and lifecycle management of privileged accounts
- Reduce standing privileges via just-in-time access controls
Pricing
£400 a unit
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
4 2 4 0 5 0 0 8 3 2 9 9 7 9 3
Contact
Protiviti LTd
Michelle Moody
Telephone: +447803902108
Email: michelle.moody@protiviti.co.uk
Planning
- Planning service
- Yes
- How the planning service works
- We work with our buyers to understand the best cloud solution for their PAM needs e.g. hosting a PAM solution in a cloud environment or purchasing a vendor hosted cloud based PAM solution. Then we support them to plan for the activities required to implement the solution and support them with design and architecture that would meet their needs e.g. on a hybrid environment. Finally we develop a plan for them with key milestones for purchasing and implementing the solution as well as plan for onboarding of applications in the PAM solution. e.g. CyberArk Privileged Cloud or CyberArk PAS solution hosted in a cloud environment (AWS, Azure, GCP etc.)
- Planning service works with specific services
- No
Training
- Training service provided
- Yes
- How the training service works
- Training varies based on the specific product or solution. Training sessions can be customised to fit the buyers needs and audience. We can run demos or training sessions ourselves or also in conjunction with our partners to demonstrate tool capabilities and how it addresses the identity risks.
- Training is tied to specific services
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
- We can work with buyers to develop a roadmap broken down into quarterly release stories to move the client from where they are now to their target state (in the cloud / new cloud service) over a relevant period of time. These stories would break down what features and functionalities would have been implemented, moved or yet to implement at each stage for total clarity.
- Setup or migration service is for specific cloud services
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- Yes
- How the quality assurance and performance testing works
- Quality is assured through our user-focused, collaborative delivery methodology and thorough testing of the solution. Protiviti's technical leads will ensure the solution satisfies both the intended end-users and established technology requirements. Our extensive quality risk management standards are applied across all global solutions, including periodic audit of specific engagements. Our models and methodologies are rigorously tested and monitored to support and maintain the quality of our solutions. We can also facilitate support from our cloud hosting partner or Secrets management supplier partner eco-system, as specified in the proposal.
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Certified security testers
- Yes
- Security testing certifications
-
- CREST
- Other
- Other security testing certifications
-
- OSCP
- OSCE
- CREST
- AWS Security Specialty
- AWS Solutions Architect
- Azure Cuber security architect
- Azure security engineer
- Certified cloud security professional
- Sailpoint certifications
- CyberArk CDE certifications
Ongoing support
- Ongoing support service
- Yes
- Types of service supported
-
- Buyer hosting or software
- Hosting or software provided by a third-party organisation
- How the support service works
-
Buyer hosting or software (e.g. CyberArk hosted in buyer environment)
Hosting or software provided by a third-party organisation (e.g.. CyberArk Privileged Cloud hosted by CyberArk)
Service scope
- Service constraints
- NA
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- 24x7x365 Monitoring
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Support levels
- Technical, throughout our engagement.
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- CyberArk licensing and professional services
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 03/04/2020
- What the ISO/IEC 27001 doesn’t cover
- N/A -covers the full range of consulting services delivered by Protiviti Ltd.
- ISO 28000:2007 certification
- Yes
- Who accredited the ISO 28000:2007
- Accredited by BSI (certificate IS 717200).
- ISO 28000:2007 accreditation date
- Last revision: 01.03.2023 (4.03.2020)
- What the ISO 28000:2007 doesn’t cover
- NA
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- SOC2
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Protiviti is committed to addressing our environmental impact and operating in an environmentally sustainable way. Our commitment to the health of our planet and its people means we seek to do our part to address our environmental impact across all areas of our organisation. Our Board-approved Global Environmental Policy sets the stage for how we operate across real estate and facilities, business processes and reporting and partnerships. We are continually strengthening our efforts to quantify, disclose and reduce our environmental footprint as we work toward setting carbon reduction goals aligned with science and increasing the amount of renewable energy we purchase. We disclose the company’s energy use and emissions, inclusive of all Robert Half and Protiviti operations, in our ESG reports and to CDP Climate Change annually. Robert Half has made progress in increasing our renewable energy purchasing. In addition to a green tariff at our sites in France that began in November 2020, we started powering our offices in Belgium, Germany and the United Kingdom with renewable electricity via green tariffs in 2021. In early 2022, we switched to a 100% green tariff for our California data centre electricity use. We will continue to make progress on carbon reduction efforts by expanding our renewable electricity purchasing, exploring electrification in buildings, and finding ways to work with our supply chain to increase adoption of carbon reduction goals.Covid-19 recovery
At Protiviti, employees' health and safety are the firm's highest priority. Protiviti offers many resources to help care for its employees and their families. These include: - Paid -Time Off: If an employee or a family member of theirs are not feeling well, employees are given advantage of paid time-off as needed. - Flexible Work and Teaming Tools: Protiviti supports and promote a flexible work environment. Employees are provided with the right to exercise their judgement in choosing to work in an area that provides them with the greatest safety, productivity and comfort given their personal situation and circumstances. - Our technology and tools empower us to work virtually and take advantage of video- conferencing and other team collaboration tools. - Regular “all hands” calls to bring people together and tom communicate key messages; Initiatives to bring our people together to chat on an informal basis – virtual “water cooler moments” Throughout the pandemic, we have focussed on bringing our people, clients, friends, partners and communities together to learn from each other and to give each other confidence in how to address the challenges of the pandemic. One such initiative was our weekly collaboration forum, which we ran for 2 years and which was open to everyone – see as an example Protiviti Collaboration Forum Series 3. https://www.protiviti.com/UK-en/collaboration-forum-series-3 While remote work can be effective and efficient, it also provides a unique set of challenges. Many of our professionals are seasoned remote workers, while others of us are new to this experience. By having a plan, using provided technology, and communicating often, we can continue to successfully add value to our clients and our teams.Tackling economic inequality
We know that our ability to make a difference in the world goes beyond the office. As an organisation, we are dedicated to supporting community service projects both at the global and local level. Our i on Hunger program unites our global community under a single purpose: to provide meals to those in need. Our efforts span across all 80 of our offices operating in 30 countries. We also empower our local offices to select causes within their own communities. The UK office’s Corporate Social Responsibility (“CSR”) team is run by London office staff. A mentoring programme is available for employees to help support students at a local school in Bermondsey through their school studies and eventually into working life. Protiviti UK is a long-standing support partner of Guy’s & St Thomas’ hospital and trust, neighbouring our office, allowing employees to come together and support the hospital’s growth and research through fundraising and volunteering initiatives. https://www.protiviti.com/UK-en/make-impact “Many areas of our business have experienced increased demand during the pandemic. During this time, we have taken the opportunity to engage more directly with job seekers pursuing changes to their careers. We have done this primarily through AWS re/Start and Capslock.” Protiviti is also one of the founding members of TC4RE. Launched in 2021, TC4RE stands for the Technology Community for Racial Equality. TC4RE supports all businesses in the technology sector, regardless of their current Diversity and Inclusion roadmap. The objective is to drive equality and self-transformation within ourselves and our organisations. TC4RE is structured through Learn, Engage, Transform in order to take individuals and organisations on a journey to build a more diverse and inclusive technology industry. Creating training and employment opportunities across the tech industry to support the employment and advancement of black and minority ethnic individuals. https://tc4re.org/Equal opportunity
Our diversity, equity and inclusion strategy is three-fold – to strengthen our diversity (workforce), to nurture a culture of inclusion (workplace) and expand our impact (marketplace). It is manifested through our leadership teams as an executive team member leads our diversity efforts and it is woven in our company values of leading oneself with integrity, leading other with inclusion, and leading our business through innovation. Our communities of connection also help us to drive our efforts. Every Protiviti office has an inclusion champion and we have employee network groups which comprise of multi-cultural groups, women and women in IT, military veterans, the LGBTQ+ community, parents, experienced hires and mental wellness. Additionally our diversity, equity and inclusion is aligned with our Learning & Development, Talent Acquisition, Performance Management, Comp & Benefits and Resource Management teams.Wellbeing
Employee Network Groups are local, grass roots groups that organise both in-person and online to promote wellbeing and diversity initiatives at Protiviti. While the activities in these groups are driven by employees, they are supported by leadership and provide our employees an “Opportunity to Have an Impact” as promised in our People Promises. iGROWW – The Initiative for Growth and Retention of Women at Work is a network of women and men to promote awareness of women’s issues, develop meaningful and mentoring relationships and share information to support the success of women at Protiviti. We strive to provide opportunities for women to connect with and support each other. We deliver programs that contribute to their personal and professional development, and act as enablers to support them to fulfil their needs at the right time in the right way. proPride UK – Protiviti UK’s LGBTQ+ and ally network which seeks to improve our business, people and communities by promoting diversity and inclusion in all our activities and dealings with colleagues, clients and others. ProCulture UK - ProCulture is committed to driving change through creating a workplace that reflect the communities we serve and where everyone feels empowered to bring their full, authentic selves to work and employees of all cultures, races, nationalities, and ethnicities feel accepted and valued. We are passionate about diversity and equality for all and celebrating the cultures of our diverse workforce. iMatter UK - iMatter is committed to creating a culture of openness with regards to mental well-being, we ultimately aim to increase the confidence of all Protiviti employees in managing their own mental health; enabling them to cope with the normal stresses of life, work productively and fruitfully, and feel able to make a contribution to their community.
Pricing
- Price
- £400 a unit
- Discount for educational organisations
- No