A.8.5
    Technological Controls

    Secure authentication

    Secure authentication technologies and procedures should be implemented based on information access restrictions and the topic-specific policy on access control.

    Purpose

    To ensure the authenticity of users and protect against unauthorized access.

    Implementation Guidance

    Implement multi-factor authentication (MFA)

    Use strong password policies

    Implement adaptive authentication based on risk

    Use modern authentication protocols (OAuth, SAML)

    Monitor authentication attempts and failures

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.5 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.5 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.5 Secure authentication. Built for compliance professionals.

    Try ISMS Copilot free