PAM Evaluation Guide

A privileged access management (PAM) evaluation compares products on a written requirements list, scores each product, and then proves the leaders in a proof of concept (POC). This guide describes the method most large buyers use and how to evaluate the AIC Enterprise Privilege Suite™ with it.

Step 1: Build the requirements list

List every requirement, then tag each one by priority. Most buyers group requirements into these areas:

Area Examples
Discovery Systems, accounts, service accounts, SSH keys, cloud keys, and where each account is used
Vault and rotation Storage, rotation, propagation to dependencies, check-out, and password rules
Sessions Brokered SSH, RDP, and VNC, recording, approvals, and command restriction
Endpoint privilege Elevation on Windows, macOS, and Linux, application control, and sudo
Identity and governance Directory integration, multi-factor authentication, roles, and access reviews
Integration and audit REST API, SIEM, ticketing, and reports
Deployment and operations Hosting options, high availability, disaster recovery, and upgrades
Commercial Licensing, support, training, and references

Start with the PAM requirements checklist. Its 127 rows describe how the suite addresses each requirement and identify planned extensions.

Step 2: Weight the requirements

A common method uses two 3-point scales and multiplies them.

Priority Weight
Must have 5
Should have 3
Nice to have 1
Fit score Meaning
5 Meets the requirement
3 Partial coverage
1 Little or no coverage

Each cell is the weight times the fit score. A product's total is the sum of its cells. A must-have the product fully meets counts 25. A nice-to-have counts at most 5. Winning the must-haves decides the result.

Step 3: Score from evidence

Ask each vendor for a status on every row, and ask for proof on the must-haves. Score only what the vendor can show. A row with no evidence scores 1.

AIC Enterprise Privilege Suite™ answers each row with one of four words:

Status Meaning
Available now Ships today. We can show it
Available now, wider scope planned Ships today for the scope described. Broader coverage is planned
Planned Not in the product yet
Organization Your organization owns this, such as a policy or a physical control

Step 4: Run the proof of concept

Take the top two or three products into a POC against your own systems. Test the scenarios that carry the most weight:

  1. Discover a test network and bring the accounts under management.
  2. Rotate a service account and confirm every dependency still runs.
  3. Open a brokered RDP and SSH session, record it, and block a restricted command.
  4. Elevate a standard user on a workstation, with and without approval.
  5. Send audit events to your SIEM and find them.
  6. Restore after a server failure.

AIC Enterprise Privilege Suite™ offers a free cloud demo environment and a 30-day on-premises evaluation. See Demo options.

Step 5: Plan the move

If you already run a PAM product, plan the migration as part of the evaluation. AIC Enterprise Privilege Suite™ imports accounts from other vault products. See Partners and migration.

Send us your RFP

Send your requirements list. We return it with the AIC Enterprise Privilege Suite™ status and evidence for every row.

Send us your RFP