ISO 27001:2022
Technological controls – ISO 27001:2022

ISO 27001:2022 8.5: Secure authentication

Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 155 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 25 controls

  • AC-11 Device Lock
  • AC-12 Session Termination
  • AC-18(1) Authentication and Encryption
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(5) Inactivity Logout
  • AC-7 Unsuccessful Logon Attempts
  • IA-11 Re-Authentication
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-3 Device Identification and Authentication
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • MA-4 Nonlocal Maintenance
  • SC-10 Network Disconnect

FedRAMP Moderate · 25 controls

  • AC-11 Device Lock
  • AC-12 Session Termination
  • AC-18(1) Authentication and Encryption
  • AC-2(1) Automated System Account Management
  • AC-2(13) Disable Accounts for High-Risk Individuals
  • AC-2(5) Inactivity Logout
  • AC-7 Unsuccessful Logon Attempts
  • IA-11 Re-Authentication
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-3 Device Identification and Authentication
  • IA-5 Authenticator Management
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1))
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4))
  • MA-4 Nonlocal Maintenance
  • SC-10 Network Disconnect

PCI DSS 4.0 · 16 controls

  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.8 8.2.8 Re-authentication after 15 minutes idle
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • 8.6.1 8.6.1 Interactive use of system accounts controlled

NIST SP 800-53 Rev 5 · 14 controls

CIS Controls v8 · 10 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices
  • CIS-4.3 Configure Automatic Session Locking on Enterprise Assets
  • CIS-5.2 Use Unique Passwords
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.4 Require MFA for Remote Network Access
  • CIS-6.5 Require MFA for Administrative Access
  • CIS-6.7 Centralize Access Control

CMMC 2.0 · 8 controls

NIST SP 800-171 Rev 3 · 6 controls

C5 (Germany) · 4 controls

  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-05 Authentication Mechanisms
  • C5-PSS-06 Session Management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified

UK Cyber Essentials · 4 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.8 Passwordless Authentication
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.6 Multi-Factor Authentication for Cloud Services

ACSC Essential Eight · 3 controls

  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ASBv3-IM-5 Use single sign-on (SSO) for application access
  • IM-4 Authenticate server and services
  • IM-6 Use strong authentication controls

SOC 2 · 3 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.6.2 User access management
  • 6.6.4 System and application access control

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-IA-2 Identification and Authentication (Organizational Users)
  • 161R1-IA-5 Authenticator Management

NIST SP 800-172 · 2 controls

  • 3.5.2e Password Manager Use
  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-REG-2 Healthcare recipient registration and identity verification

COBIT 2019 · 1 control

  • DSS05.04 DSS05.04 Manage user identity and logical access

DORA · 1 control

ISO 27001:2013 · 1 control

ISO 27002:2022 · 1 control

  • 8.5 Secure authentication
  • Art. 2-septies(7) Art. 2-septies(7) Use biometrics for physical and logical access to data only within the safeguard measures

NIS2 Directive · 1 control

  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 8.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.