Password and authentication standard
How authentication information is issued, protected, changed and revoked, and where multi-factor authentication is required.
How the register reads it
| Also called | password policy, MFA standard, credential standard |
|---|---|
| Family | Access and identity |
| Document type | Standard. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the access control policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The head of IT operations. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | NIS2 is ticked and no line resolves to it or to its parent (ISO 27001, ISO 27701 require it too, inside a parent document, so they do not list it separately). |
| Template | Password management policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 5.17 Authentication informationControl allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
What the ISO 27002 guidance expects the document to say: Requires a management process to control how authentication information is issued and looked after over time, including guidance to personnel on handling it appropriately.
Common gap: Policies exist but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.5 Secure authenticationImplement authentication technologies and procedures based on access restrictions and policy.
What the ISO 27002 guidance expects the document to say: Requires secure authentication technologies and procedures to be implemented, driven by the information access restrictions and the topic specific policy on access control.
Common gap: Reliance on static passwords only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 A.3.23 Secure authenticationWhere required by the customer, the organization shall provide the capability for secure log-on procedures for any user accounts under the customer's control, in addition to applying secure authentication to its own accounts on systems that process PII.
Common gap: Customer accounts limited to password-only log-on with no stronger option
Source: ISO/IEC 27701:2025
The NIS2 Directive
NIS2 Art. 21(2)(j) Multi-factor or continuous authentication, secured communications and secured emergency communicationsThis point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always coverage: remote access, administrative access, and access to the systems behind the essential service are where absence matters most. Secured voice, video and text communications within the entity is the second limb. The third, secured emergency communication systems, is the one most often absent, and it is the one that decides whether the entity can coordinate during an incident in which its normal collaboration and directory services are unavailable or untrusted. A crisis plan that runs on the corporate messaging platform does not satisfy this if that platform is what has been compromised.
Common gap: Multi-factor authentication on the corporate portal but not on administrative or machine access paths
Source: NIS2 Directive
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerIdentity and access management standard · Privileged access management policy