A.5.17
    Organizational Controls

    Authentication information

    Allocation and management of authentication information should be controlled by a management process, including advising personnel on appropriate handling of authentication information.

    Purpose

    To ensure the secure management of authentication credentials throughout their lifecycle.

    Implementation Guidance

    Implement strong password policies (complexity, length, expiration)

    Securely distribute initial passwords and require immediate change

    Never transmit passwords in clear text

    Use multi-factor authentication where possible

    Implement password managers for credential storage

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.17 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.17 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.17 Authentication information. Built for compliance professionals.

    Try ISMS Copilot free