Build Series Vol. 06 — Identity & Access
One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.
One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.
The decision this volume is really about: the authenticator model, and a break-glass path that does not depend on the thing it recovers.
Control mapping first. The exact SOC 2, ISO 27001:2022, NIST CSF 2.0, CIS v8.1, CMMC, PCI DSS v4.0.1 and HIPAA clauses this build satisfies are printed before any installation step, so the work becomes audit evidence rather than a side effect of it.
A validation harness, not just a build. How to prove the control works and — the part nothing free covers — how to catch it failing quietly: the expired scan credential, the canary that stopped, the encryption key nobody can recover, the segmentation your diagram claims and your firewall does not.
Three sized architectures with honest hour counts. Tier 1 is 25–40 hrs to build · 4–6 hrs a month.
Stack: Keycloak · Authentik · Zitadel · OpenBao · Vaultwarden · FIDO2 and passkeys.
Current as of August 2026. NIST SP 800-63-4 is final and superseded 800-63-3 on 1 August 2025, with synced passkeys explicitly accommodated. "Do we have MFA" stopped being the right question — proxy phishing and infostealers both end with a stolen session, so lifetime, binding and revocation are controls in their own right.
Every volume runs the same nine sections: prerequisites, control mapping, the decisions that matter, three sized architectures, a build runbook, a validation harness, an evidence pack, an operating cadence with honest hour counts, failure modes and the buy line, and an AI prompt pack.
Reading order: read 3rd of ten. Each volume stands alone, and each is cheaper to build if the one before it exists.
Ships without support. This is a document, not a service contract — and Section 8 tells you plainly where the buy line is.
Also available in 7 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Build Series Foundation Bundle
Volumes 02, 01 and 06 — inventory, detection and identity. The three everything else depends on.
Open SOC Architecture + Build Foundation
The Open SOC Reference Architecture plus Build Series Volumes 02, 01 and 06 — the system-level design, then the three planes everything else depends on.
SOC 2 + Build Foundation
SOC 2 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
ISO 27001 + Build Foundation
ISO 27001:2022 Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
HIPAA + Build Foundation
HIPAA Readiness Accelerator plus Build Series Volumes 02, 01 and 06 — the workbook that identifies the requirements, and the three volumes that make them real.
Complete Build Series
All ten volumes in reading order — a security department built out of open source, with control mappings, validation harnesses and honest buy lines throughout. 29% off buying separately.
Open SOC Architecture + Complete Build Series
The reference architecture and all ten build volumes — the whole system-level design plus every plane built end to end, in the recommended build order. 30% off buying separately.
What's included
- PDF — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
Complete your toolkit
More from the CISO Marketplace ecosystem
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee