We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Identity & Access

Identity and access management (IAM)

Assessment, design and implementation of access control that holds up in an audit — single sign-on, multi-factor authentication, privileged access and access certification, delivered by the same team that has to evidence it under PCI DSS, ISO 27001 and SOC 2.

What we typically deliver

  • Current-state assessment of joiner/mover/leaver, privileged access, service accounts and access review practice — with the gaps ranked by audit and breach exposure, not by tooling preference.
  • Target-state design: authentication standards, role model, segregation of duties and the identity lifecycle you can actually operate.
  • Implementation of SSO (SAML/OIDC), MFA including phishing-resistant factors, privileged access management and identity governance with access certification.
  • Integration with the HR system as the joiner/leaver source of truth, so deprovisioning stops depending on someone remembering.
  • Post-implementation validation and the evidence pack your assessor will ask for — configuration, approvals, review records.

Where access control actually fails

Access findings are the most common serious observations we raise in audits, and they are rarely about the identity product. They are about the operating model around it:

  • Leavers who never left. Accounts disabled in the directory but still live in a SaaS app that was never wired to it.
  • Movers. People who changed role three times and kept every permission from all three. This is the failure auditors probe hardest, because it is invisible until you look.
  • Service and machine accounts with no owner, no rotation and standing privilege — increasingly the highest-risk population in a cloud estate.
  • Access reviews that rubber-stamp. A quarterly certification approved in bulk in four minutes is evidence of a process, not of control.
  • MFA with holes. Enforced on the SSO front door, absent on legacy VPN, break-glass accounts and the administrative console someone uses at 2am.
  • Standing administrative privilege where just-in-time elevation would remove the exposure entirely.

What your framework actually requires

IAM is where several obligations converge, which is why fixing it once usually satisfies more than one assessor:

  • ISO/IEC 27001:2022 — Annex A 5.15 access control, 5.16 identity management, 5.17 authentication information and 5.18 access rights.
  • PCI DSS v4 — Requirement 7 (need-to-know access) and Requirement 8 (identify and authenticate), including the expanded multi-factor expectations.
  • SOC 2 — CC6, the logical access criteria, where evidence of provisioning, review and removal is tested across the observation period.
  • RBI, SEBI and sector regulators — privileged access, segregation of duties and periodic recertification are standard examination topics.

Why CyberSigma

We assess and implement, which matters more than it sounds: the team designing your role model is the team that has had to defend access evidence in a PCI DSS assessment and a SOC 2 examination. That tends to produce a design that survives an audit rather than one that merely looks tidy in the console. We are CERT-In empanelled and a PCI SSC-listed QSA company.

Related

Access control sits alongside data loss prevention (who can reach the data, and what leaves with them), ITGC audits where access is one of the core control families, and VAPT, which is where weak authorisation is usually proven rather than assumed.

Free tool
PCI DSS Scope Checker
See if you’re in scope and your likely SAQ type or level — free, in under a minute.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

IAM — common questions

Do you assess IAM, implement it, or both?

Both. Engagements often start as an assessment against a framework obligation and continue into design and implementation of SSO, MFA, privileged access management and access certification. You can also engage us for the assessment alone if you have an internal or partner team who will build it.

Which IAM platforms do you work with?

We are not tied to a vendor. Platform selection follows the requirement — your existing directory and cloud estate, the applications in scope, the regulatory obligations and the team who has to run it. Where you have already chosen a platform we work within it rather than restarting the decision.

What does an IAM assessment cover?

The identity lifecycle end to end: joiner, mover and leaver processes; privileged and administrative access; service and machine accounts; authentication standards including MFA coverage and gaps; the role model and segregation of duties; and how access reviews are performed and evidenced. Findings map to your framework — ISO 27001 Annex A 5.15 to 5.18, PCI DSS Requirements 7 and 8, or SOC 2 CC6.

Our auditor flagged access reviews. Is that an IAM problem or a process problem?

Usually process. Most organisations can produce a review; fewer can show that reviewers had enough context to make a real decision, that exceptions were followed up, and that removals actually happened. We fix the operating model and the evidence trail alongside any tooling change, because tooling alone does not close that finding.

How long does an IAM programme take?

An assessment is typically a few weeks depending on the number of applications, directories and user populations. Implementation is phased — authentication and SSO first, then privileged access, then governance and certification — because a single cutover across everything is where these programmes usually fail. Scope determines the timeline, which is what a scoping call establishes.

Ready to discuss your Identity & access management requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →