NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(5)(ii)(D): Password Management (Addressable)

Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 10 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 8.3.10 8.3.10 Service provider customer password guidance
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

UK Cyber Essentials · 5 controls

  • CE-FW.2 Change Default Firewall Passwords
  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.7 Educate Users on Strong Passwords
  • CE-SC.8 Process for Compromised Passwords

CMMC 2.0 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services

C5 (Germany) · 3 controls

  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

FedRAMP High · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators

FedRAMP Moderate · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • IM-3 Manage application identities securely and automatically

CIS Controls v8 · 2 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-5.2 Use Unique Passwords

ISO 27001:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ISO 27002:2022 · 1 control

  • 5.17 Authentication information

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

NIST SP 800-172 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.