ISO27001:2022 – A5.17 Authentication information
Introduction to ISO 27001 – A5.17
In A5.16 (Identity Management), we covered the full life cycle of identities. ISO 27001 – A5.17 builds on that by specifying how authentication information should be controlled and managed.
What does ISO 27001 – A5.17 require?
The standard states:
“Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information.” (ISO 27001 – A5.17 – Authentication Information)
What is authentication information?
Authentication information is used to verify that an individual or system is who they claim to be, granting access to systems or facilities accordingly. Common types include:
- Username: An identifier such as an email or account name
- Password or PIN: A secret known only to the user
- Biometric data: Fingerprint, facial recognition, retina scans
- Secret tokens: Codes generated by an authentication app or sent to a device
When two or more of these are combined, it’s called Multi-Factor Authentication (MFA), commonly known as Two-Factor Authentication (2FA).
Why is this required?
Authentication is critical to prevent cyber incidents or data breaches. Using 2FA or MFA significantly reduces the chances of unauthorised access. Just as you protect your personal bank account with these methods, your business systems need similar safeguards.
What the auditor is looking for
While no formal policy is required, you must be able to show that:
- A process exists for allocating authentication information (e.g. during onboarding)
- Password policies include strength, length, and reset procedures
- Users are educated on proper handling of login credentials
This can be demonstrated through onboarding documentation, training records, or IT support tickets showing password resets and 2FA setups.
Q & A
Do I need a written policy?
No, but you do need to show that the process exists. This could be evidenced through user education materials, internal documentation, or use of authentication tools like Microsoft Authenticator or Google Authenticator.
How often should passwords be changed?
There’s a myth that passwords should be changed regularly. In practice, this often leads to poor habits. Instead:
- Use a strong, unique password or passphrase
- Only change passwords when there’s evidence of compromise
- Never reuse the same password across systems
Difficulty rating
We rate this a 1 out of 5. It requires minimal technical skill, though familiarity with terms like 2FA and MFA is useful. Your IT lead should help implement the appropriate methods.
More questions?
ISO27001 controls are interrelated. Review our FAQs or cross-references to better understand how this fits with identity management, user provisioning, and RBAC. Need help implementing authentication best practices? Reach out – we’re happy to support you.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.
