View Categories

A5.17: Authentication Information

4 min read

Authentication information refers to the credentials used to verify a user’s identity before granting access to systems, applications, or data. This includes passwords, biometric data, security tokens, smart cards, and multi-factor authentication (MFA) mechanisms.

ISO 27001 A.5.17 mandates organizations to implement strong authentication measures to prevent unauthorized access, identity theft, and credential misuse. Weak authentication methods can lead to cyberattacks such as phishing, brute-force attacks, credential stuffing, and session hijacking.

Implementation Guide #

Step 1: Define Authentication Policies

Organizations should establish a clear authentication policy covering:

  • Password requirements (length, complexity, expiration).
  • Multi-Factor Authentication (MFA) enforcement.
  • Use of biometrics or hardware tokens for critical access.
  • Session timeout and automatic logout settings.
  • How authentication failures are handled (e.g., account lockout).

Step 2: Implement Secure Authentication Methods

  1. Password-Based Authentication
  • Minimum password length: At least 12–16 characters.
  • Complexity requirements: Mix of uppercase, lowercase, numbers, and special characters.
  • Password expiration: Avoid frequent forced changes (instead, use breach detection).
  • Use of passphrases: Encourage passphrases instead of complex passwords (e.g., “BlueSky!Ride$24”).

Recommended Tools:

  • Password Managers: Bitwarden, 1Password, LastPass.
  • Breach Detection: Have I Been Pwned API, Microsoft Defender SmartScreen.
  1. Multi-Factor Authentication (MFA)
  • Enforce MFA for all privileged accounts and sensitive systems.
  • Use a combination of:
    • Something you know: Password, PIN.
    • Something you have: One-time password (OTP), smart card, security token.
    • Something you are: Biometrics (fingerprint, facial recognition).

Recommended MFA Solutions:

  • Authenticator Apps: Google Authenticator, Microsoft Authenticator, Authy.
  • Hardware Tokens: YubiKey, RSA SecurID, Feitian.
  1. Passwordless Authentication
  • Use biometrics, FIDO2 security keys, and Single Sign-On (SSO) for a more secure experience.
  • Implement Federated Identity Management (FIM) to authenticate across multiple platforms without passwords.

Recommended Solutions:

  • Microsoft Azure AD Passwordless Authentication.
  • Okta Adaptive MFA.
  • Google Passkeys & Apple Face ID.
  1. Secure Storage of Authentication Data
  • Never store passwords in plain text.
  • Use hashed and salted storage with algorithms like bcrypt, PBKDF2, or Argon2.
  • Enforce TLS encryption for all authentication transactions.

Recommended Tools:

  • Hashing & Encryption: OpenSSL, HashiCorp Vault.
  • Identity Providers (IdP): AWS Cognito, Auth0, Google Identity.

Step 3: Authentication Monitoring & Security

What to Do:

  • Monitor login attempts for suspicious activity (failed logins, logins from unusual locations).
  • Enforce risk-based authentication (RBA) to require MFA for high-risk logins.
  • Enable alerts for unusual authentication behaviors (multiple failed attempts, impossible travel logins).

Recommended SIEM & Monitoring Tools:

  • Splunk Security Cloud.
  • IBM QRadar.
  • Microsoft Defender for Identity.

What Not to Do:

  • Do not use default passwords. Change them immediately upon setup.
  • Never reuse passwords across different accounts. Use unique ones.
  • Avoid using SMS for MFA if possible. Use authenticator apps or hardware tokens instead.

Templates #

  • Authentication Policy Template.
  • Password Management Guidelines.
  • MFA Implementation Checklist.

Example Scenario #

A financial institution mandates passwordless authentication using FIDO2 security keys and biometric verification for high-risk transactions.

Without strong authentication, an attacker using a credential-stuffing attack could access accounts using previously leaked passwords, leading to financial fraud.

How to Comply #

To comply with ISO 27001 A.5.17, organizations should:

  • Implement secure authentication mechanisms such as MFA and passwordless authentication.
  • Store authentication information securely using strong hashing algorithms.
  • Continuously monitor authentication events for anomalies.

How to Pass an Audit #

Key Documents to Prepare:

  • Authentication Policy and Procedures.
  • MFA Implementation Reports.
  • Logs of authentication failures and security incidents.

What the Auditor Will Check: #

  • Are authentication methods strong and compliant with industry best practices?
  • Are passwords securely stored and hashed?
  • Is MFA enforced where necessary?

Top 3 Mistakes Organizations Make #

  1. Using weak or shared passwords – Leads to easy credential compromise.
  2. Not enforcing MFA – Makes it easier for attackers to bypass authentication.
  3. Storing passwords improperly – Risk of database breaches and credential leaks.

ISO 27001 Authentication Information FAQ #

Q1: Why is SMS-based MFA not recommended?
SMS-based MFA is vulnerable to SIM swapping attacks and interception by attackers. Use authenticator apps or hardware tokens instead.

Q2: How often should users change passwords?
Only when there’s evidence of compromise. Frequent password changes often lead to weaker security (users choosing predictable passwords).

Q3: What’s the best way to secure admin accounts?
Use Privileged Access Management (PAM) tools like CyberArk, BeyondTrust, and enforce Just-in-Time (JIT) access.

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.5.17 Authentication Information Preventive, Risk-Based, Operational
Purpose Ensure secure authentication methods
Applicability All authentication systems and identity providers
ISO 27001 Domains Authentication, Access Control, IT Security

Authentication security is the first line of defense against cyber threats. Weak authentication can lead to data breaches, identity theft, and financial losses.

Action Step: Review your authentication policies today—implement MFA, strong password policies, and secure authentication storage to enhance security.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now