ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.5: Secure authentication

Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose: authenticate users and other entities securely whenever they are given access to systems, applications and services. Guidance: choose an authentication technique suited to proving the claimed identity of users, software, messages and other entities, with strength matched to the classification of what is being accessed. When identity must be proven strongly, rely on something other than a password, for example certificates, smart cards, hardware tokens or biometric traits. Access to critical systems should use multi-factor authentication combining something known, held and inherent, which can be extended with rule-based step-up when access comes from an unusual location, device or time. Compromised biometric data should be invalidated, and because biometrics can fail in some conditions (moisture, ageing) at least one alternative technique should be available. Log-on should be designed to minimize unauthorized access by: not revealing sensitive system or application details until log-on succeeds; showing a notice that only authorized users may access the system; giving no help during log-on that could aid an intruder, such as saying which part of the input was wrong; validating the log-on only once all input is complete; resisting brute force through CAPTCHA, forced reset after a set number of failures or lockout; logging failed and successful attempts; raising a security event and alerting the user and administrators when a possible attack on log-on controls is seen; showing or sending separately, after success, when the last successful log-on happened and any failed tries since then; hiding passwords as typed, unless this must be relaxed for accessibility or to avoid repeated lockouts; never sending passwords in clear text across networks; ending sessions after a period of inactivity, especially in public or external locations and on endpoints; and limiting connection times for high-risk applications. Other information: ISO/IEC 29115 covers entity authentication assurance.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 186 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 24 controls

  • AC-11 Device Lock
  • AC-12 Session Termination
  • AC-17(4) Privileged Commands and Access
  • AC-2(5) Inactivity Logout
  • AC-6 Least Privilege
  • AC-7 Unsuccessful Logon Attempts
  • AC-8 System Use Notification
  • IA-11 Re-Authentication
  • IA-12 Identity Proofing (IA-12)
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-7 Cryptographic Module Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • MA-4 Nonlocal Maintenance

FedRAMP Moderate · 24 controls

  • AC-11 Device Lock
  • AC-12 Session Termination
  • AC-17(4) Privileged Commands and Access
  • AC-2(5) Inactivity Logout
  • AC-6 Least Privilege
  • AC-7 Unsuccessful Logon Attempts
  • AC-8 System Use Notification
  • IA-11 Re-Authentication
  • IA-12 Identity Proofing (IA-12)
  • IA-12(5) Identity Proofing | Address Confirmation (IA-12(5))
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication (IA-2(5))
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • IA-2(8) Access to Accounts Replay Resistant
  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(2) Public Key-Based Authentication
  • IA-6 Authentication Feedback
  • IA-7 Cryptographic Module Authentication
  • IA-8 Identification and Authentication (Non-Organizational Users)
  • IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators (IA-8(2))
  • MA-4 Nonlocal Maintenance

ACSC Essential Eight · 18 controls

  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • E8-MFA-ISM-0974 Multi-factor authentication (ISM-0974): Multi-factor authentication is used to authenticate unprivileged users of systems
  • E8-MFA-ISM-1173 Multi-factor authentication (ISM-1173): Multi-factor authentication is used to authenticate privileged users of systems
  • E8-MFA-ISM-1401 Multi-factor authentication (ISM-1401): Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are
  • E8-MFA-ISM-1504 Multi-factor authentication (ISM-1504): Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data
  • E8-MFA-ISM-1505 Multi-factor authentication (ISM-1505): Multi-factor authentication is used to authenticate users of data repositories
  • E8-MFA-ISM-1679 Multi-factor authentication (ISM-1679): Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data
  • E8-MFA-ISM-1680 Multi-factor authentication (ISM-1680): Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data
  • E8-MFA-ISM-1681 Multi-factor authentication (ISM-1681): Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data
  • E8-MFA-ISM-1682 Multi-factor authentication (ISM-1682): Multi-factor authentication used for authenticating users of systems is phishing-resistant
  • E8-MFA-ISM-1872 Multi-factor authentication (ISM-1872): Multi-factor authentication used for authenticating users of online services is phishing-resistant
  • E8-MFA-ISM-1873 Multi-factor authentication (ISM-1873): Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option
  • E8-MFA-ISM-1874 Multi-factor authentication (ISM-1874): Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant
  • E8-MFA-ISM-1892 Multi-factor authentication (ISM-1892): Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data
  • E8-MFA-ISM-1893 Multi-factor authentication (ISM-1893): Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data
  • E8-MFA-ISM-1894 Multi-factor authentication (ISM-1894): Multi-factor authentication used for authenticating users of data repositories is phishing-resistant

NIST SP 800-53 Rev 5 · 15 controls

PCI DSS 4.0 · 15 controls

  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 8.2.3 8.2.3 Service provider unique factors per customer
  • 8.2.8 8.2.8 Re-authentication after 15 minutes idle
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.3.11 8.3.11 Tokens, smart cards and certificates individually assigned
  • 8.3.3 8.3.3 Identity verified before factor changes
  • 8.3.4 8.3.4 Lockout after 10 attempts for 30 minutes
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass

CMMC 2.0 · 10 controls

  • ISM-0487 Restrictions on passwordless SSH logins
  • ISM-0974 Multi-factor authentication for unprivileged users
  • ISM-1173 Multi-factor authentication for privileged users
  • ISM-1403 Account lockout after failed logons
  • ISM-1546 Authenticating users before access
  • ISM-1919 Disabling authentication protocols without MFA
  • ISM-1920 Preventing MFA self-enrolment from untrustworthy devices

CIS Controls v8 · 7 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices
  • CIS-5.2 Use Unique Passwords
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.4 Require MFA for Remote Network Access
  • CIS-6.5 Require MFA for Administrative Access

MTCS (Singapore) · 6 controls

  • 14.7 System and network session management
  • 22.5 Account lockout
  • 22.8 Administrator access security
  • 23.3 User access security
  • 23.5 User account lockout
  • 23.8 User session management
  • ASBv3-IM-5 Use single sign-on (SSO) for application access
  • IM-4 Authenticate server and services
  • IM-6 Use strong authentication controls
  • IM-7 Restrict resource access based on conditions

C5 (Germany) · 4 controls

  • C5-IDM-03 Locking and withdrawal of user accounts in the event of inactivity or multiple failed logins
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-05 Authentication Mechanisms
  • C5-PSS-06 Session Management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified

NIST SP 800-171 Rev 3 · 4 controls

UK Cyber Essentials · 4 controls

  • CE-AC.2 Authenticate Users Before Granting Access
  • CE-AC.8 Passwordless Authentication
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.6 Multi-Factor Authentication for Cloud Services
  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible

ETSI EN 303 645 · 3 controls

  • 16.1.31.C.06 16.1.31.C.06 Consider location-based authentication factors
  • 16.1.38.C.01 16.1.38.C.01 Risk-assess passwordless authentication options
  • 16.7.44.C.01 16.7.44.C.01 MFA design considerations (first listing)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • SEC.AUTH.MFA Multi-factor authentication for all staff and end users (DSP-controlled products)
  • SEC.AUTH.SESSION Session, lockout, remember-me and token limits

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.6 Access control
  • 6.6.2 User access management

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-IA-2 Identification and Authentication (Organizational Users)
  • 161R1-IA-5 Authenticator Management

NIST SP 800-172 · 2 controls

  • 3.5.2e Password Manager Use
  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components

NIST SP 800-66 Rev 2 · 2 controls

  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • MYHR-REG-2 Healthcare recipient registration and identity verification

DORA · 1 control

IEC 62443 · 1 control

  • 62443-3-3-FR1-SR-1-1 Human User Identification and Authentication (FR1)

ISO 27001:2022 · 1 control

  • 8.5 Secure authentication

NIS2 Directive · 1 control

  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications

NY DFS 23 NYCRR 500 · 1 control

SOC 2 · 1 control

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • TSA-SD-06 Access control to Critical Cyber Systems
  • MTSA-Access-Control Access Control for Security Related Systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 186 it maps to, and the evidence behind each claim, over MCP and REST.