Identity
Security

Security starts with identity. We help organizations build a solid identity and access management strategy — reducing risk, strengthening control over users and privileges, and establishing governance processes that improve security, operational efficiency, and audit readiness.

Identity Security Services

Specialized assessments in identity and access

Four complementary assessments covering the full identity management lifecycle — from core Active Directory infrastructure to access governance and the corporate IAM ecosystem.

AD Security & Readiness Assessment

A static, non-intrusive audit of your core identity infrastructure (on-premise Active Directory). Identifies security gaps, insecure configurations, and structural vulnerabilities with no operational impact.

Phase 01

Evidence and configuration collection via secure remote access — GPO reports, admin console snapshots. 100% passive, no exploitation testing.

Phase 02

Defensive analysis and Remediation Blueprint with findings, criticality level, and concrete actions aligned to CIS Controls v8, NIST, and Microsoft Security Best Practices.

CIS Controls v8 NIST MS Security Best Practices

PAM Security Assessment

A consultative evaluation of the current state, hardening policies, and design of your Privileged Access Management (PAM) solution. Vendor-agnostic: CyberArk, BeyondTrust, Delinea, FortiPAM, or open source.

Phase 01

Baseline extraction — review of vault policies, credential rotation, session recording, and approval flows for critical accounts.

Phase 02

Operational gap analysis against vendor secure-implementation guides, with a detailed remediation action plan.

NIST SP 800-53 ISO 27001 A.8.2 Least Privilege

Identity Governance & Compliance Assessment

An assessment of the maturity of your identity governance processes — Joiner/Mover/Leaver lifecycle, Segregation of Duties (SoD) controls, and access certification campaigns.

Phase 01

Identity Lifecycle & Role Mapping Review — provisioning processes, role matrices (RBAC/ABAC), and deprovisioning mechanisms.

Phase 02

Compliance & Segregation Plan — identification of SoD conflicts and an identity governance strategy aligned with the business.

NIST CSF 2.0 SOX Section 404 PCI DSS v4.0

Workforce IAM Security Assessment

An audit of your corporate IAM/IdP platform — analyzing the strength of application federation (SAML, OIDC, OAuth), SSO architecture, and secure credential management to detect identity silos.

Phase 01

Access Channels Audit — review of authentication policies, credential management, and corporate IdP configuration.

Phase 02

Federation & SSO Architecture Review — assessing how centralized the application ecosystem is under a consistent, best-practice-aligned authentication strategy.

SAML / OIDC / OAuth Zero Trust CIS Controls

Contact

Do you know who has access to what in your organization?

Fill out the form and a specialist will get in touch with you shortly.





    Differentiators

    Why choose BASE4 Security?

    01

    A technology-agnostic approach

    We're not tied to a single vendor. We assess and recommend based on the client's real environment — whether that's CyberArk, Entrust, SailPoint, Okta, Microsoft Entra, or any other identity platform.

    02

    Zero operational impact

    All of our identity assessments are strictly analytical and non-intrusive. We don't impact operations or compromise business continuity during the evaluation.

    03

    Real audit readiness

    Every deliverable includes the governance structure and documentation your organization needs to successfully face internal and external audits related to identity, access, and regulatory compliance.

    Evaluated technologies

    The sale, support, and implementation of these technologies is managed together with our Network Security team.

    Frequently asked questions

    Everything you need to know about Identity Security

    What does an Identity Security Assessment cover, and how is it different from a pentest?

    An Identity Security Assessment is an analytical, non-intrusive evaluation that reviews configurations, policies, architecture, and identity management processes — without exploiting vulnerabilities or generating operational impact. A pentest simulates real attacks to validate controls at a specific point in time. Identity assessments are broader in scope and safer to run in critical production environments.

    Why is it critical to review Active Directory security?

    90% of successful cyberattacks exploit pre-existing insecure Active Directory configurations. It's the central nervous system of identity in most organizations — if it's misconfigured, every control built on top of it is fragile. A periodic review is the most effective way to close that vector before it's exploited.

    What is Segregation of Duties (SoD) and why does it matter?

    Segregation of Duties is the principle that prevents a single person from carrying out actions that require cross-control — for example, creating a vendor and approving its payment. In identity environments, SoD conflicts occur when a user accumulates permissions that are incompatible with each other. Without SoD controls, the risk of internal fraud and critical errors rises significantly, and SOX or PCI DSS auditors flag it as a major finding.

    Does the PAM assessment apply if we use an open source solution?

    Yes. Our approach is vendor-agnostic — we assess the security logic and hardening of the solution regardless of whether it's CyberArk, Entrust, Delinea, FortiPAM, or an open source solution. What we validate is whether the platform meets the real principle of least privilege and is configured according to security best practices.

    What regulatory frameworks do Identity Security assessments cover?

    Depending on the type of assessment:
    • AD Security: CIS Controls v8 (controls 5 and 6), NIST, and Microsoft Security Best Practices
    • PAM: NIST SP 800-53 Rev. 5 (AC-2 and AC-6) and ISO/IEC 27001:2022 (A.8.2)
    • IGA: NIST CSF 2.0, SOX Section 404, and PCI DSS v4.0 (Requirements 7 and 8)
    • IAM: Zero Trust, CIS Controls, and federation standards (SAML, OIDC, OAuth)

    How long does an identity assessment take?

    It depends on the scope and complexity of the environment. In general, each individual assessment takes between 2 and 4 weeks from kickoff to final report delivery. Specific timelines are defined during scoping, once the client's environment has been surveyed.