Identity
Security
Security starts with identity. We help organizations build a solid identity and access management strategy — reducing risk, strengthening control over users and privileges, and establishing governance processes that improve security, operational efficiency, and audit readiness.
Specialized assessments in identity and access
Four complementary assessments covering the full identity management lifecycle — from core Active Directory infrastructure to access governance and the corporate IAM ecosystem.
AD Security & Readiness Assessment
A static, non-intrusive audit of your core identity infrastructure (on-premise Active Directory). Identifies security gaps, insecure configurations, and structural vulnerabilities with no operational impact.
Evidence and configuration collection via secure remote access — GPO reports, admin console snapshots. 100% passive, no exploitation testing.
Defensive analysis and Remediation Blueprint with findings, criticality level, and concrete actions aligned to CIS Controls v8, NIST, and Microsoft Security Best Practices.
PAM Security Assessment
A consultative evaluation of the current state, hardening policies, and design of your Privileged Access Management (PAM) solution. Vendor-agnostic: CyberArk, BeyondTrust, Delinea, FortiPAM, or open source.
Baseline extraction — review of vault policies, credential rotation, session recording, and approval flows for critical accounts.
Operational gap analysis against vendor secure-implementation guides, with a detailed remediation action plan.
Identity Governance & Compliance Assessment
An assessment of the maturity of your identity governance processes — Joiner/Mover/Leaver lifecycle, Segregation of Duties (SoD) controls, and access certification campaigns.
Identity Lifecycle & Role Mapping Review — provisioning processes, role matrices (RBAC/ABAC), and deprovisioning mechanisms.
Compliance & Segregation Plan — identification of SoD conflicts and an identity governance strategy aligned with the business.
Workforce IAM Security Assessment
An audit of your corporate IAM/IdP platform — analyzing the strength of application federation (SAML, OIDC, OAuth), SSO architecture, and secure credential management to detect identity silos.
Access Channels Audit — review of authentication policies, credential management, and corporate IdP configuration.
Federation & SSO Architecture Review — assessing how centralized the application ecosystem is under a consistent, best-practice-aligned authentication strategy.
Do you know who has access to what in your organization?
Fill out the form and a specialist will get in touch with you shortly.
Why choose BASE4 Security?
A technology-agnostic approach
We're not tied to a single vendor. We assess and recommend based on the client's real environment — whether that's CyberArk, Entrust, SailPoint, Okta, Microsoft Entra, or any other identity platform.
Zero operational impact
All of our identity assessments are strictly analytical and non-intrusive. We don't impact operations or compromise business continuity during the evaluation.
Real audit readiness
Every deliverable includes the governance structure and documentation your organization needs to successfully face internal and external audits related to identity, access, and regulatory compliance.
The sale, support, and implementation of these technologies is managed together with our Network Security team.
Everything you need to know about Identity Security
What does an Identity Security Assessment cover, and how is it different from a pentest?
Why is it critical to review Active Directory security?
What is Segregation of Duties (SoD) and why does it matter?
Does the PAM assessment apply if we use an open source solution?
What regulatory frameworks do Identity Security assessments cover?
- AD Security: CIS Controls v8 (controls 5 and 6), NIST, and Microsoft Security Best Practices
- PAM: NIST SP 800-53 Rev. 5 (AC-2 and AC-6) and ISO/IEC 27001:2022 (A.8.2)
- IGA: NIST CSF 2.0, SOX Section 404, and PCI DSS v4.0 (Requirements 7 and 8)
- IAM: Zero Trust, CIS Controls, and federation standards (SAML, OIDC, OAuth)


