Control objective
Security culture aligns incentives, skills, authority, and habits so teams identify risk, review changes, report problems, respond, and recover without depending on exceptional individuals. Culture must produce observable system behavior.
Operating practices
Assign control and service owners. Protect time for review, threat modeling, tests, exercises, maintenance, and learning. Make reporting safe. Use separation of duties for high-impact changes. Rotate response and recovery practice across the team.
Evidence
Measure review quality, expired access, exception age, exercise results, detection and containment time, recovery success, unresolved action items, ownership gaps, and repeated bypass. Do not use training completion alone as the signal.
Failure and residual risk
Blame hides incidents. Hero culture concentrates access and knowledge. Security gates without service ownership create bypass. Metrics can be gamed. Leadership statements without authority and time do not change control behavior.
Pomerium boundary
Pomerium can make access policy and decision evidence visible. Organizations own incentives, staffing, review, incident practice, recovery, application ownership, and action on evidence. A tool cannot create accountable operating culture by itself.
Evaluation checklist
- Does every access control and service have an empowered owner?
- Can staff report mistakes and incidents without hiding evidence?
- Are review, expiry, exercises, response, and recovery normal scheduled work?
- Do measures track control outcomes instead of activity alone?
- Can the team operate and recover without one privileged expert?
