This article introduces Identity Attack Path Management (Identity APM) as a new security practice to address how attackers exploit privilege chains to access critical assets. It presents a Maturity Model based on the CMMI framework to help organizations evaluate their capability across six levels, from nonexistent to optimizing, providing a structured way to identify gaps and improve.