ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.17: Authentication information

A management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 78 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 12 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 2.3.2 2.3.2 Wireless encryption keys changed on triggers
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.3.10 8.3.10 Service provider customer password guidance
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas

CMMC 2.0 · 5 controls

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-IA-1 IA-1 Policy and Procedures
  • NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
  • NIST800-IA-5 IA-5 Authenticator Management
  • SP800-53-IA Identification and Authentication Family

UK Cyber Essentials · 4 controls

  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.7 Educate Users on Strong Passwords
  • CE-SC.8 Process for Compromised Passwords
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • IM-3 Manage application identities securely and automatically

C5 (Germany) · 3 controls

  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

CIS Controls v8 · 3 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.2 Use Unique Passwords

FedRAMP High · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators

FedRAMP Moderate · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators

ISO 27001:2013 · 3 controls

  • A.9.2.4 Management of secret authentication information of users
  • A.9.3.1 Use of secret authentication information
  • A.9.4.3 Password management system
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.6.2 User access management
  • 6.6.3 User responsibilities

NIS2 Directive · 2 controls

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

CMMC 2.0 Level 1 · 1 control

  • NET-4 NET-4 Keep passwords confidential and demand them only when an absent employee's post holds indispensable information

COBIT 2019 · 1 control

  • DSS05.06 DSS05.06 Manage sensitive documents and output devices

DORA · 1 control

ISO 27002:2022 · 1 control

  • 5.17 Authentication information

NIST SP 800-172 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.