ISO 27001 Annex A 5.17 Authentication information controls how organisations manage secret authentication details like passwords, passcodes, and tokens. Formal rules prevent unauthorised account access, protect credentials from theft, and keep systems secure.
Table of contents
Key Takeaways
- Manage secret credential lifecycles: Create clear rules for creating, changing, storing, and retiring secret authentication information.
- Store rules centrally: Keep access policies, password guidelines, and management records in a central document repository.
- Ban shared credentials: Require every user to have personal, unique login details to maintain clear individual accountability.
- Protect credentials during setup: Issue temporary secrets securely and force users to change them upon first login.
- Enforce multi-factor checks: Require extra authentication steps for all remote logins, administrative portals, and critical systems.
- Secure secret storage: Store passwords and secret keys using strong one-way encryption rather than plain text.
- Change default secrets: Replace factory-set passwords on all new hardware and software tools before deployment.
- Cancel compromised secrets fast: Reset authentication details immediately whenever you suspect credential theft or data exposure.
How to Implement ISO 27001 Annex A 5.17
- Draft an authentication policy: Write clear guidelines for managing secret authentication information and publish them centrally.
- Set strong password standards: Mandate minimum password lengths, complex character mixes, and blocks against common, weak phrases.
- Deliver temporary secrets securely: Use separate, secure communication paths when sending initial passcodes to new starters.
- Force first-login password changes: Configure systems to require users to replace temporary setup passwords right away.
- Deploy central credential managers: Provide approved password management tools so staff can generate and store complex passcodes safely.
- Secure authentication backends: Encrypt all stored user secrets using salted hashes and block plain-text transmissions.
- Turn on account lockout limits: Lock accounts automatically after multiple failed login attempts to prevent brute-force attacks.
- Train staff on credential safety: Teach employees never to write down passwords on paper, share codes, or reuse personal secrets.
- Enforce immediate offboarding resets: Revoke personal secrets and reset shared administrative keys as soon as team members leave.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.17
- Review authentication policies: Inspect written procedures to confirm standard rules govern the full lifecycle of authentication secrets.
- Verify system complexity settings: Check system configurations to ensure technical rules enforce password length, lockout limits, and expiry terms.
- Audit new starter credential paths: Review the onboarding process to verify temporary passwords travel through secure, private channels.
- Inspect stored credential tables: Verify that databases and directories store passwords exclusively as protected cryptographic hashes.
- Test default password changes: Sample newly installed equipment and applications to confirm teams replaced factory-default passwords.
- Check multi-factor enforcement: Test access to key business portals to confirm multi-factor authentication triggers for all users.
- Conduct clean desk walkthroughs: Check physical office areas to verify workers do not keep written passwords on sticky notes or whiteboards.
- Review leaver revocation timing: Confirm that system teams disable authentication records promptly upon employee departure.
Audit Evidence Checklist
- Authentication information policy: Maintain a documented password and credential management policy with full revision history.
- System configuration screenshots: Supply evidence showing active technical rules for password length, history, and lockout thresholds.
- Multi-factor configuration reports: Provide dashboard exports proving multi-factor authentication is mandatory across all systems.
- New user setup logs: Provide audit tickets showing secure delivery of temporary credentials and mandatory first-use changes.
- Clean desk audit records: Supply inspection logs from spot checks verifying no plain-text passwords exist in work areas.
- Default password change records: Maintain commissioning checklists proving factory passwords were reset during equipment setup.
- Staff training logs: Show sign-off sheets proving workers finished security awareness training on protecting secret credentials.
What to Teach Employees
- Keep secrets confidential: Teach workers never to reveal passwords, passcodes, or multi-factor tokens to anyone, including managers.
- Never write down credentials: Instruct staff never to store passcodes on sticky notes, notebooks, or unencrypted text files.
- Use approved password vaults: Encourage employees to store complex, unique passwords inside company-approved password tools.
- Avoid password reuse: Warn workers against using the same secret password across work systems and personal web accounts.
- Spot credential theft attempts: Train staff to identify deceptive phishing messages designed to harvest logins and security codes.
- Report exposed secrets fast: Ensure employees know to report suspected password leaks immediately so administrators can reset access.
Common Implementation Challenges
- Writing passwords on paper: Staff keep sticky notes on monitors to remember complex passcodes. Supply password managers to eliminate written notes.
- Sharing generic accounts: Teams share a single login to save money or time. Require unique, individual user accounts for every worker.
- Sending secrets via email: Administrators email clear-text passwords to new starters. Deliver credentials using separate secure communication channels.
- Retaining default passwords: Teams leave factory passwords on routers and tools. Block devices from network access until default secrets are changed.
- Password reuse across tools: Users pick one easy password for every business application. Enforce single sign-on and password managers.
- Delayed resets after compromise: Teams wait to reset compromised logins. Automate immediate account locks when suspicious logins occur.
How to Measure Effectiveness (KPIs)
- Multi-factor coverage rate: Measure the percentage of active user accounts protected by mandatory multi-factor authentication.
- Password policy compliance rate: Track the proportion of systems enforcing technical length, complexity, and lockout controls.
- Credential breach incident count: Monitor the total number of security events caused by compromised, stolen, or shared passwords.
- Compromised secret reset speed: Measure the average time taken to revoke and replace authentication details after a reported leak.
- Password manager adoption rate: Track the percentage of staff actively using approved password vaults for work accounts.
- Authentication audit finding count: Count the number of non-conformities raised against authentication controls during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.17 connects to several other ISO 27001 requirements:
Annex A 5.17 relies on Clause 5.15 (Access Control) for high-level rules. It supports Clause 5.18 (Access Rights) by providing the mechanism for verification. This control also links to Clause 8.2 (Privileged Access Rights) for administrative secrets. Finally: it connects to Clause 8.5 (Secure Authentication) for technical configuration requirements.

