Skip to main content

Operate and recover access systems

Govern, observe, detect, investigate, preserve evidence, contain, recover, and assure an identity-aware access system.

Learning outcomes

  • Maintain an owned inventory and risk assessment for each access path.
  • Govern and deploy policy and configuration with tests and drift detection.
  • Turn intelligence, telemetry, detections, and triage into supported response decisions.
  • Preserve evidence and reconstruct identity-aware access activity across system boundaries.
  • Recover known-good service, trust, and authority, then prove old authority fails.

Scenario

A sensitive route changes from a narrow group rule to a broad domain rule. The team must detect the drift, identify affected requests, contain harmful access, restore the intended rule, and confirm no bypass remains.

Ordered learning units

  1. Concept

    Access System Inventory

    Inventory protected resources, identities, routes, policies, credentials, dependencies, owners, and recovery paths.

  2. Concept

    Shared Responsibility for Access

    Shared responsibility assigns each access control, dependency, decision, evidence source, and recovery action to an owner.

  3. Guide

    Assess risk in an access path

    Connect assets, threats, likelihood, impact, controls, evidence, assumptions, and residual risk for one access system.

  4. Guide

    Build an access audit trail

    Join authentication, authorization, proxy, and application evidence without confusing one event for another.

  5. Concept

    Sensitive Security Logging

    Record useful access evidence while preventing credentials, excess personal data, tampering, and indefinite retention.

  6. Concept

    Security Telemetry

    Security telemetry uses logs, metrics, traces, and events to answer defined detection, investigation, and control questions.

  7. Concept

    MITRE ATT&CK

    MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.

  8. Concept

    Cyber Threat Intelligence

    Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.

  9. Concept

    Indicator of Compromise and TTP

    Distinguish short-lived technical observables from adversary tactics, techniques, and procedures used to build more durable detection and response.

  10. Concept

    Detection Quality

    Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.

  11. Concept

    Security Alert Triage

    Qualify, categorize, prioritize, enrich, assign, and escalate a potential incident from evidence, asset criticality, identity, scope, and impact.

  12. Concept

    Threat Hunting

    Proactively test a bounded threat hypothesis in existing evidence when no alert has yet confirmed the activity.

  13. Concept

    Malware

    Understand malicious code that steals, persists, disrupts, spies, moves, or changes systems and prepare to contain and rebuild affected trust.

  14. Concept

    Denial of Service

    Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.

  15. Guide

    Contain compromised access

    Disable identity, revoke credentials and sessions, isolate routes, and measure the last accepted harmful action.

  16. Concept

    Backup and Restore

    Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.

  17. Guide

    Recover an access system

    Restore known-good identity, policy, trust, routes, evidence, and service after compromise or control failure.

  18. Concept

    Security Postmortem

    A security postmortem turns an incident timeline, contributing conditions, and response evidence into owned system changes.

  19. Concept

    Secure System Decommissioning

    Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.

  20. Concept

    Security and Compliance

    Security protects stated assets and properties, while compliance evaluates obligations against defined criteria and evidence.

Evaluation questions

  • Can one protected action be reconstructed across identity, decision, proxy, and application evidence?
  • Can the team turn relevant intelligence into a tested detection or hunt, then triage the result with explicit confidence?
  • Can the team preserve evidence, detect drift or bypass, and measure the last accepted action after containment?
  • Can recovery restore approved access while old identity, session, credential, and route authority fail?

Completion conditions

  • Operate one staged change from risk and review through deployment, evidence, and rollback.
  • Complete an unauthorized-access exercise with triage, evidence preservation, containment, clean recovery, and independent negative tests.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo