ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-10: Define and Verify Password Selection and Sizing Rules

Define rules on the choice and length of passwords and verify that they are applied.

What else in your programme already covers this

This control maps to 43 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 4 controls

  • 8.3.1 All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you
  • 8.3.6 If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they meet the following minimum level of complexity: • A minimum length of 12 characters (or IF the system does not support 12
  • 8.3.7 Password history
  • 8.3.8 Authentication policy communicated

CMMC 2.0 · 3 controls

  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • IM-6 Use strong authentication controls

C5 (Germany) · 2 controls

CIS Controls v8 · 2 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-5.2 Use Unique Passwords

FedRAMP High · 2 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication

FedRAMP Moderate · 2 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication

ISO 27002:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.9 Device Unlocking Credentials and Brute-Force Protection
  • ASD37-21 Disable local administrator accounts (Excellent)

NIST SP 800-172 · 1 control

  • IA-5 Authenticator Management
  • IA-5 Authenticator Management
  • IA-5 Authenticator Management

SOC 2 · 1 control

  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ANSSI Hygiene III: Authenticate and Control Access (measures 8 to 13)

You are reading one control. How much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) have you already done?

ANSSI Guide d'hygiene informatique (42 mesures, v2.0) ANSSI-HYG-10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ANSSI Guide d'hygiene informatique (42 mesures, v2.0) your existing evidence covers. Hold FedRAMP Moderate and 35 of 42 ANSSI Guide d'hygiene informatique (42 mesures, v2.0) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 43 it maps to, and the evidence behind each claim, over MCP and REST.