Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose: authenticate users and other entities securely whenever they are given access to systems, applications and services. Guidance: choose an authentication technique suited to proving the claimed identity of users, software, messages and other entities, with strength matched to the classification of what is being accessed. When identity must be proven strongly, rely on something other than a password, for example certificates, smart cards, hardware tokens or biometric traits. Access to critical systems should use multi-factor authentication combining something known, held and inherent, which can be extended with rule-based step-up when access comes from an unusual location, device or time. Compromised biometric data should be invalidated, and because biometrics can fail in some conditions (moisture, ageing) at least one alternative technique should be available. Log-on should be designed to minimize unauthorized access by: not revealing sensitive system or application details until log-on succeeds; showing a notice that only authorized users may access the system; giving no help during log-on that could aid an intruder, such as saying which part of the input was wrong; validating the log-on only once all input is complete; resisting brute force through CAPTCHA, forced reset after a set number of failures or lockout; logging failed and successful attempts; raising a security event and alerting the user and administrators when a possible attack on log-on controls is seen; showing or sending separately, after success, when the last successful log-on happened and any failed tries since then; hiding passwords as typed, unless this must be relaxed for accessibility or to avoid repeated lockouts; never sending passwords in clear text across networks; ending sessions after a period of inactivity, especially in public or external locations and on endpoints; and limiting connection times for high-risk applications. Other information: ISO/IEC 29115 covers entity authentication assurance.
This control maps to 186 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-MFA-ISM-0974 Multi-factor authentication (ISM-0974): Multi-factor authentication is used to authenticate unprivileged users of systems
E8-MFA-ISM-1173 Multi-factor authentication (ISM-1173): Multi-factor authentication is used to authenticate privileged users of systems
E8-MFA-ISM-1401 Multi-factor authentication (ISM-1401): Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are
E8-MFA-ISM-1504 Multi-factor authentication (ISM-1504): Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data
E8-MFA-ISM-1505 Multi-factor authentication (ISM-1505): Multi-factor authentication is used to authenticate users of data repositories
E8-MFA-ISM-1679 Multi-factor authentication (ISM-1679): Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data
E8-MFA-ISM-1680 Multi-factor authentication (ISM-1680): Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data
E8-MFA-ISM-1681 Multi-factor authentication (ISM-1681): Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data
E8-MFA-ISM-1682 Multi-factor authentication (ISM-1682): Multi-factor authentication used for authenticating users of systems is phishing-resistant
E8-MFA-ISM-1872 Multi-factor authentication (ISM-1872): Multi-factor authentication used for authenticating users of online services is phishing-resistant
E8-MFA-ISM-1873 Multi-factor authentication (ISM-1873): Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option
E8-MFA-ISM-1874 Multi-factor authentication (ISM-1874): Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant
E8-MFA-ISM-1892 Multi-factor authentication (ISM-1892): Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data
E8-MFA-ISM-1893 Multi-factor authentication (ISM-1893): Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data
E8-MFA-ISM-1894 Multi-factor authentication (ISM-1894): Multi-factor authentication used for authenticating users of data repositories is phishing-resistant
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.