top of page


Risk-Based Dynamic Access Rules: Meeting CISA ZTMM Conditional Access Requirements Under OMB M-22-09
Most civilian agencies still have a practical problem at the access layer: users are granted access based on static roles, but the risk around that user changes throughout the day. The user may move from a managed laptop to an unmanaged device. The session may originate from an unusual location. The endpoint may fall out of compliance. The account may show abnormal behavior. If the access decision does not change when the risk changes, the agency is not operating at OMB M-22-
Jun 297 min read


CISA ZTMM User Pillar: Building Dynamic Privilege Rules for OMB M-22-09 Identity Requirements
Most civilian agencies still have a privilege problem hiding inside normal operations: static Active Directory groups, standing administrator roles, VPN-era access assumptions, and quarterly access reviews that do not respond to user risk in the moment. That model does not hold up against the CISA ZTMM User Pillar or the identity direction in OMB M-22-09. Explore how conditional user access has to move from policy language into enforceable rules.
Jun 157 min read


DTM 25-003 Dynamic Privilege Controls: How DoD Programs Should Implement Periodic Authentication Rules
Explore the intricacies of DTM 25-003 and how DoD programs should implement periodic authentication rules. Explore how DTM 25-003 requires deciding, in near real time, whether that user should keep the same privileges after the mission, device, behavior, or risk context changes.
Jun 126 min read
bottom of page
