ISO/IEC 27000 Authentication Information, v2022

Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to authentication information.

Assessment Step

1
Authentication Information (AuthenticationInformation)
Is the allocation and management of authentication information controlled by a management process, including guidance to personnel on appropriate handling?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Authentication Information
Allocation and management of authentication information shall be controlled by a management process, including advising personnel on appropriate handling of authentication information.
Citations
27001
Annex A, Control 5.17
27002
Section 5.17