A management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose: make entity authentication work correctly and prevent authentication processes from failing. Guidance on allocation: temporary passwords or PINs generated at enrolment are unguessable, unique per person and must be changed after first use; a user's identity is verified before new, replacement or temporary authentication information is issued; authentication information is delivered securely over an authenticated, protected channel and never in clear text email; users confirm receipt; vendor default credentials are changed immediately after installation; and significant allocation and management events are recorded confidentially using an approved method such as a password vault. User responsibilities: keep secret authentication information confidential and never share personal secrets, with secrets for shared or non-personal identities disclosed only to authorized people; change credentials at once when compromise is notified or suspected; choose strong passwords that are not guessable from personal details, not dictionary words, use memorable passphrases with mixed characters and meet a minimum length; do not reuse passwords across services; and have these duties written into employment terms (6.2). A password management system should let users choose and change passwords with a confirmation step, enforce strength, force change at first login, force change when needed (after an incident, or when someone who knew a shared password leaves or changes job), block reuse, reject common passwords and credentials known from breaches, hide passwords as typed, and store and transmit them protected, with hashing and encryption per approved cryptography (8.24). Other information: keys, smart card tokens and biometrics are other forms of authentication information (see ISO/IEC 24760); forcing frequent password changes can backfire; SSO and password vaults reduce what users must protect but raise the impact of a disclosure; where an independent authority assigns passwords, the user-selection, first-login and forced-change items do not apply.
This control maps to 116 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-ADMIN-ISM-1685 Restrict administrative privileges (ISM-1685): Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.