Frameworks / ISO 27001:2022 / 8.5 ISO 27001:2022
Technological controls – ISO 27001:2022
ISO 27001:2022 8.5: Secure authentication Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 155 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-11 Device Lock AC-12 Session Termination AC-18(1) Authentication and Encryption AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(5) Inactivity Logout AC-7 Unsuccessful Logon Attempts IA-11 Re-Authentication IA-12(5) Identity Proofing | Address Confirmation (IA-12(5)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-2(8) Access to Accounts Replay Resistant IA-3 Device Identification and Authentication IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-6 Authentication Feedback IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) MA-4 Nonlocal Maintenance SC-10 Network Disconnect AC-11 Device Lock AC-12 Session Termination AC-18(1) Authentication and Encryption AC-2(1) Automated System Account Management AC-2(13) Disable Accounts for High-Risk Individuals AC-2(5) Inactivity Logout AC-7 Unsuccessful Logon Attempts IA-11 Re-Authentication IA-12(5) Identity Proofing | Address Confirmation (IA-12(5)) IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(2) MFA to Non-Privileged Accounts IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5)) IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6)) IA-2(8) Access to Accounts Replay Resistant IA-3 Device Identification and Authentication IA-5 Authenticator Management IA-5(2) Public Key-Based Authentication IA-6 Authentication Feedback IA-8 Identification and Authentication (Non-Organizational Users) IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies (IA-8(1)) IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2)) IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles (IA-8(4)) MA-4 Nonlocal Maintenance SC-10 Network Disconnect 8.2.2 8.2.2 Shared and generic IDs only by exception 8.2.3 8.2.3 Service provider unique factors per customer 8.2.8 8.2.8 Re-authentication after 15 minutes idle 8.3.1 8.3.1 Access authenticated with at least one factor 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned 8.3.3 8.3.3 Identity verified before factor changes 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes 8.3.6 8.3.6 Password minimum length 12 and complexity 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass 9.2.3 9.2.3 Physical protection of network hardware and lines 7.3.1 7.3.1 Need-to-know access control system covers all components 8.6.1 8.6.1 Interactive use of system accounts controlled CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.9 Deploy Port-Level Access Control CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices CIS-4.3 Configure Automatic Session Locking on Enterprise Assets CIS-5.2 Use Unique Passwords CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.4 Require MFA for Remote Network Access CIS-6.5 Require MFA for Administrative Access CIS-6.7 Centralize Access Control C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins C5-IDM-09 Authentication mechanisms C5-PSS-05 Authentication Mechanisms C5-PSS-06 Session Management NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified CE-AC.2 Authenticate Users Before Granting Access CE-AC.8 Passwordless Authentication CE-SC.5 Password-Based Authentication Quality CE-SC.6 Multi-Factor Authentication for Cloud Services E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1 E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2 E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3 ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services ANSSI-HYG-13 Prefer Strong Authentication Where Possible ASBv3-IM-5 Use single sign-on (SSO) for application access IM-4 Authenticate server and services IM-6 Use strong authentication controls SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) 6.6.2 User access management 6.6.4 System and application access control 161R1-IA-2 Identification and Authentication (Organizational Users) 161R1-IA-5 Authenticator Management 3.5.2e Password Manager Use 3.5.3e Prohibit Connection of Unknown or Unverified System Components AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment MYHR-REG-2 Healthcare recipient registration and identity verification DSS05.04 DSS05.04 Manage user identity and logical access 8.5 Secure authentication Art. 2-septies(7) Art. 2-septies(7) Use biometrics for physical and logical access to data only within the safeguard measures Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technological controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 8.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.