ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.17: Authentication information

A management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose: make entity authentication work correctly and prevent authentication processes from failing. Guidance on allocation: temporary passwords or PINs generated at enrolment are unguessable, unique per person and must be changed after first use; a user's identity is verified before new, replacement or temporary authentication information is issued; authentication information is delivered securely over an authenticated, protected channel and never in clear text email; users confirm receipt; vendor default credentials are changed immediately after installation; and significant allocation and management events are recorded confidentially using an approved method such as a password vault. User responsibilities: keep secret authentication information confidential and never share personal secrets, with secrets for shared or non-personal identities disclosed only to authorized people; change credentials at once when compromise is notified or suspected; choose strong passwords that are not guessable from personal details, not dictionary words, use memorable passphrases with mixed characters and meet a minimum length; do not reuse passwords across services; and have these duties written into employment terms (6.2). A password management system should let users choose and change passwords with a confirmation step, enforce strength, force change at first login, force change when needed (after an incident, or when someone who knew a shared password leaves or changes job), block reuse, reject common passwords and credentials known from breaches, hide passwords as typed, and store and transmit them protected, with hashing and encryption per approved cryptography (8.24). Other information: keys, smart card tokens and biometrics are other forms of authentication information (see ISO/IEC 24760); forcing frequent password changes can backfire; SSO and password vaults reduce what users must protect but raise the impact of a disclosure; where an independent authority assigns passwords, the user-selection, first-login and forced-change items do not apply.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 116 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 14 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.2 8.3.2 Authentication factors unreadable with strong cryptography
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 8.3.9 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis
  • 9.2.4 9.2.4 Locking of consoles in sensitive areas
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

FedRAMP High · 8 controls

  • IA-2 Identification and Authentication (Organizational Users)
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))
  • IA-6 Authentication Feedback
  • PS-4 Personnel Termination

FedRAMP Moderate · 8 controls

  • IA-2 Identification and Authentication (Organizational Users)
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-5(6) Protection of Authenticators
  • IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators (IA-5(7))
  • IA-6 Authentication Feedback
  • PS-4 Personnel Termination
  • ISM-1402 Protecting stored credentials
  • ISM-1558 Constructing word-sequence passphrases
  • ISM-1590 Changing compromised or exposed user credentials
  • ISM-1593 Identity verification before issuing credentials
  • ISM-1594 Secure delivery of new credentials
  • ISM-1595 Changing credentials on first use
  • ISM-1847 Changing KRBTGT account credentials

MTCS (Singapore) · 7 controls

  • 22.12 Secure transmission of access credentials
  • 22.3 Generation of administrator passwords
  • 22.6 Password change
  • 22.7 Password reset and first logon
  • 23.4 User access password
  • 23.6 User password reset and first logon change
  • 23.7 Password protection

CMMC 2.0 · 5 controls

HIPAA Security Rule · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-IA-1 IA-1 Policy and Procedures
  • NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
  • NIST800-IA-5 IA-5 Authenticator Management
  • NIST800-IA-6 IA-6 Authentication Feedback
  • SP800-53-IA Identification and Authentication Family

NIST SP 800-66 Rev 2 · 5 controls

  • ASBv3-DP-6 Use a secure key management process
  • ASBv3-IM-2 Protect identity and authentication systems
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • IM-3 Manage application identities securely and automatically

UK Cyber Essentials · 4 controls

  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.7 Educate Users on Strong Passwords
  • CE-SC.8 Process for Compromised Passwords
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services

C5 (Germany) · 3 controls

  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

CIS Controls v8 · 3 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-5.2 Use Unique Passwords

ETSI EN 303 645 · 3 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified

NIST SP 800-171 Rev 3 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

ACSC Essential Eight · 2 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-ADMIN-ISM-1685 Restrict administrative privileges (ISM-1685): Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)
  • PROC.PRODUCTID Keep ATO product IDs confidential and use them only as intended
  • SEC.AUTH.SSO Enterprise single sign-on only on DPO advice and within set limits

NIS2 Directive · 2 controls

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • 16.1.37.C.01 16.1.37.C.01 Password manager master passwords follow agency policy
  • 3.5.4.C.02 3.5.4.C.02 User obligations for authenticators and account use
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

CMMC 2.0 Level 1 · 1 control

DORA · 1 control

ISO 27001:2022 · 1 control

  • 5.17 Authentication information

NIST SP 800-172 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.17 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 116 it maps to, and the evidence behind each claim, over MCP and REST.