Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 8.5 Secure authentication
ISO/IEC 27001:2022 Annex A 8.5 Secure authentication
Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services.
Steps that cite it
- KC-01 S6 Decide the vendor's access
Evidence commonly asked for
- Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats
- An authentication standard linking required authentication strength to information classification and system criticality
- MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules
- Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry
Accepted citation forms are listed on the answer format page.