Table of contents
ISO/IEC 27001:2022 Annex A 5.17
ISO 27001 Annex A 5.17 Authentication information controls how organisations manage secret authentication details like passwords, passcodes, and tokens. Formal rules prevent unauthorised account access, protect credentials from theft, and keep systems secure.
Key Takeaways
- Manage secret credential lifecycles: Create clear rules for creating, changing, storing, and retiring secret authentication information.
- Store rules centrally: Keep access policies, password guidelines, and management records in a central document repository.
- Ban shared credentials: Require every user to have personal, unique login details to maintain clear individual accountability.
- Protect credentials during setup: Issue temporary secrets securely and force users to change them upon first login.
- Enforce multi-factor checks: Require extra authentication steps for all remote logins, administrative portals, and critical systems.
- Secure secret storage: Store passwords and secret keys using strong one-way encryption rather than plain text.
- Change default secrets: Replace factory-set passwords on all new hardware and software tools before deployment.
- Cancel compromised secrets fast: Reset authentication details immediately whenever you suspect credential theft or data exposure.
How to Implement ISO 27001 Annex A 5.17
- Draft an authentication policy: Write clear guidelines for managing secret authentication information and publish them centrally.
- Set strong password standards: Mandate minimum password lengths, complex character mixes, and blocks against common, weak phrases.
- Deliver temporary secrets securely: Use separate, secure communication paths when sending initial passcodes to new starters.
- Force first-login password changes: Configure systems to require users to replace temporary setup passwords right away.
- Deploy central credential managers: Provide approved password management tools so staff can generate and store complex passcodes safely.
- Secure authentication backends: Encrypt all stored user secrets using salted hashes and block plain-text transmissions.
- Turn on account lockout limits: Lock accounts automatically after multiple failed login attempts to prevent brute-force attacks.
- Train staff on credential safety: Teach employees never to write down passwords on paper, share codes, or reuse personal secrets.
- Enforce immediate offboarding resets: Revoke personal secrets and reset shared administrative keys as soon as team members leave.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Annex A 5.17
- Review authentication policies: Inspect written procedures to confirm standard rules govern the full lifecycle of authentication secrets.
- Verify system complexity settings: Check system configurations to ensure technical rules enforce password length, lockout limits, and expiry terms.
- Audit new starter credential paths: Review the onboarding process to verify temporary passwords travel through secure, private channels.
- Inspect stored credential tables: Verify that databases and directories store passwords exclusively as protected cryptographic hashes.
- Test default password changes: Sample newly installed equipment and applications to confirm teams replaced factory-default passwords.
- Check multi-factor enforcement: Test access to key business portals to confirm multi-factor authentication triggers for all users.
- Conduct clean desk walkthroughs: Check physical office areas to verify workers do not keep written passwords on sticky notes or whiteboards.
- Review leaver revocation timing: Confirm that system teams disable authentication records promptly upon employee departure.
Audit Evidence Checklist
- Authentication information policy: Maintain a documented password and credential management policy with full revision history.
- System configuration screenshots: Supply evidence showing active technical rules for password length, history, and lockout thresholds.
- Multi-factor configuration reports: Provide dashboard exports proving multi-factor authentication is mandatory across all systems.
- New user setup logs: Provide audit tickets showing secure delivery of temporary credentials and mandatory first-use changes.
- Clean desk audit records: Supply inspection logs from spot checks verifying no plain-text passwords exist in work areas.
- Default password change records: Maintain commissioning checklists proving factory passwords were reset during equipment setup.
- Staff training logs: Show sign-off sheets proving workers finished security awareness training on protecting secret credentials.
What to Teach Employees
- Keep secrets confidential: Teach workers never to reveal passwords, passcodes, or multi-factor tokens to anyone, including managers.
- Never write down credentials: Instruct staff never to store passcodes on sticky notes, notebooks, or unencrypted text files.
- Use approved password vaults: Encourage employees to store complex, unique passwords inside company-approved password tools.
- Avoid password reuse: Warn workers against using the same secret password across work systems and personal web accounts.
- Spot credential theft attempts: Train staff to identify deceptive phishing messages designed to harvest logins and security codes.
- Report exposed secrets fast: Ensure employees know to report suspected password leaks immediately so administrators can reset access.
Common Implementation Challenges
- Writing passwords on paper: Staff keep sticky notes on monitors to remember complex passcodes. Supply password managers to eliminate written notes.
- Sharing generic accounts: Teams share a single login to save money or time. Require unique, individual user accounts for every worker.
- Sending secrets via email: Administrators email clear-text passwords to new starters. Deliver credentials using separate secure communication channels.
- Retaining default passwords: Teams leave factory passwords on routers and tools. Block devices from network access until default secrets are changed.
- Password reuse across tools: Users pick one easy password for every business application. Enforce single sign-on and password managers.
- Delayed resets after compromise: Teams wait to reset compromised logins. Automate immediate account locks when suspicious logins occur.
How to Measure Effectiveness (KPIs)
- Multi-factor coverage rate: Measure the percentage of active user accounts protected by mandatory multi-factor authentication.
- Password policy compliance rate: Track the proportion of systems enforcing technical length, complexity, and lockout controls.
- Credential breach incident count: Monitor the total number of security events caused by compromised, stolen, or shared passwords.
- Compromised secret reset speed: Measure the average time taken to revoke and replace authentication details after a reported leak.
- Password manager adoption rate: Track the percentage of staff actively using approved password vaults for work accounts.
- Authentication audit finding count: Count the number of non-conformities raised against authentication controls during internal audits.
Related ISO 27001 Controls
ISO 27001 Control A 5.17 connects to several other ISO 27001 requirements:
Annex A 5.17 relies on Clause 5.15 (Access Control) for high-level rules. It supports Clause 5.18 (Access Rights) by providing the mechanism for verification. This control also links to Clause 8.2 (Privileged Access Rights) for administrative secrets. Finally: it connects to Clause 8.5 (Secure Authentication) for technical configuration requirements.
