Zero Trust Security Scoreboard
The Zero Trust Security Scoreboard provides a quantitative assessment of your PAM-Pro deployment's infrastructure hardening posture. While regulatory frameworks assess organizational processes, the Security Scoreboard focuses strictly on technical implementation controls, encryption parameters, and identity boundaries.
Differentiated Governance Tabs
To keep distinct administrative domains clear and manageable, PAM-Pro organizes governance into three dedicated tabs under the Governance menu:
- Framework Compliance: Dynamic 0-100 continuous compliance scoring, violation detection, and regulatory control mappings (NIST 800-53, SOC 2, HIPAA, PCI-DSS).
- Zero Trust Security Scoreboard: Point-based infrastructure hardening checklist evaluating technical configurations across identity, data, network, and operational tiers.
- Access Requests: Centralized interface for reviewing, approving, and auditing Just-In-Time elevation requests.
The 120-Point Scoring System
The Security Scoreboard evaluates your deployment across four critical security disciplines, offering a maximum score of 120 points:
1. Identity Controls
- MFA Sign-In Verification (+15 pts): Validates that all administrative sessions authenticate through Entra ID with multi-factor authentication, verified via the
amrauthentication context token claim. - Checkout Step-Up MFA (+15 pts): Enforces step-up authentication at the moment of credential checkout via Entra ID Authentication Contexts.
- Device Compliance (+15 pts): Restricts portal access to Microsoft Intune-compliant, managed corporate endpoints via Conditional Access policies.
- Risk-Based Rotation (+10 pts): Integrates with Entra ID Identity Protection to trigger automated credential rotation upon high-risk sign-in events.
2. Data & Key Controls
- Immutable Audit Storage - WORM (+15 pts) - Auto-verified: Automatically verifies that the underlying Azure Blob Storage audit container enforces Write-Once, Read-Many immutability policies.
- Envelope Encryption Hardening (+10 pts): Verifies that tenant credentials are encrypted using Argon2id envelope key derivation meeting OWASP minimum security parameters.
- HSM-Backed Key Vault (+10 pts) - Optional Add-on: Upgrades key custody to Azure Key Vault Managed HSM (FIPS 140-3 Level 3 compliance).
3. Network Controls
- Location-Based Access Control (+10 pts): Restricts PAM-Pro administration to trusted corporate IP ranges, VPN gateways, or named locations.
- Enforce TLS 1.3 (+5 pts) - Auto-verified: Confirms that edge proxies and client transports disallow legacy TLS 1.1 or 1.2 handshakes.
4. Operations Controls
- Zero Backend Client Secrets (+15 pts) - Auto-verified: Validates that the application authenticates to Azure resources solely using System-Assigned Managed Identities and Workload Identity Federation, with zero stored API keys or client secrets.
Attestation Preservation & Live Verification
Certain hardening items are evaluated live by the backend (e.g., TLS cipher checks and WORM storage verification), while others represent external administrative controls configured in Entra ID. PAM-Pro ensures that manual attestations made by administrators are safely preserved across live checks and navigation changes, preventing checkboxes from reverting during routine page visits.
Integration with Auditor Evidence
Whenever you export an evidence bundle from the Framework Compliance tab, the current state of the Zero Trust Security Scoreboard is automatically embedded into the SOC2 Security Brief. This provides auditors with verifiable proof of both your process controls and technical infrastructure hardening.
© 2026 Huntoso LLC. All rights reserved.