Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(5)(ii)(D) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(5)(ii)(D): Password Management (Addressable) Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 60 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
2.2.2 2.2.2 Vendor default accounts managed 2.2.6 2.2.6 System security parameters configured against misuse 8.3.10 8.3.10 Service provider customer password guidance 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic 8.3.5 8.3.5 Initial and reset passwords unique and changed 8.3.6 8.3.6 Password minimum length 12 and complexity 8.3.7 8.3.7 No reuse of last four passwords 8.3.8 8.3.8 Authentication policies communicated to users 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts 8.6.3 8.6.3 System account passwords protected against misuse CE-FW.2 Change Default Firewall Passwords CE-SC.2 Change Default Passwords on Devices and Software CE-SC.5 Password-Based Authentication Quality CE-SC.7 Educate Users on Strong Passwords CE-SC.8 Process for Compromised Passwords ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules ANSSI-HYG-11 Protect Passwords Stored on Systems ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services C5-IDM-08 Confidentiality of authentication information C5-IDM-09 Authentication mechanisms C5-PSS-07 Confidentiality of Authentication Information IA-5 Authenticator Management IA-5(1) Password-Based Authentication IA-5(6) Protection of Authenticators IA-5 Authenticator Management IA-5(1) Password-Based Authentication IA-5(6) Protection of Authenticators ASD37-21 Disable local administrator accounts (Excellent) ASD37-23 Protect authentication credentials (Excellent) ASBv3-IM-8 Restrict the exposure of credential and secrets IM-3 Manage application identities securely and automatically CIS-14.3 Train Workforce Members on Authentication Best Practices CIS-5.2 Use Unique Passwords 5.17 Authentication information 8.5 Secure authentication NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment 5.17 Authentication information 6.6.2 User access management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.