A.5.17A.5 Organizational controls

Authentication information

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.17 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Ensure entities are properly authenticated and prevent failures in authentication processes.

How to meet this control

In short: Control allocation and management of authentication information (passwords, keys).

  1. Step 01Mandate a password manager and enforce strong, unique passwords with breached-password blocking through your identity provider
  2. Step 02Require multi-factor authentication on email, admin, VPN and remote access at a minimum
  3. Step 03Verify identity before issuing or resetting credentials and force a change of any temporary secret on first use
  4. Step 04Change all default vendor credentials immediately on installation and never send credentials in clear-text email
  5. Step 05Store secrets in protected form (hashing or a vault) and brief users not to share authentication information

Tip: Mandate a password manager and MFA; never email credentials.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Control allocation and management of authentication information through a defined process
  • ›Generate temporary secrets that are non-guessable and unique, and force a change after first use
  • ›Verify a user's identity before issuing new, replacement or temporary credentials
  • ›Transmit authentication information securely and avoid sending it in clear-text email
  • ›Change default vendor credentials immediately after installation
  • ›Advise users to keep secret authentication information confidential and not to share it
  • ›Enforce strong passwords, prevent reuse, block compromised passwords and store them in protected form
  • ›Consider tools like single sign-on or password vaults to reduce the burden of managing secrets

Audit evidence to keep

  • - Password and authentication policy specifying strength, MFA and reset rules
  • - MFA configuration evidence across email, admin and remote access
  • - Records of identity verification before credential issue or reset
  • - Evidence that default credentials are changed and secrets are stored protected

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.17. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.