Policy Register

Password and authentication standard

How authentication information is issued, protected, changed and revoked, and where multi-factor authentication is required.

How the register reads it

Also calledpassword policy, MFA standard, credential standard
FamilyAccess and identity
Document typeStandard. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the access control policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe head of IT operations.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenNIS2 is ticked and no line resolves to it or to its parent (ISO 27001, ISO 27701 require it too, inside a parent document, so they do not list it separately).
TemplatePassword management policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.17 Authentication information

Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.

What the ISO 27002 guidance expects the document to say: Requires a management process to control how authentication information is issued and looked after over time, including guidance to personnel on handling it appropriately.

Evidence an auditor accepts: The process for allocating authentication information, including initial issue, secure delivery and forced change on first use; rules on strength, reuse, expiry and storage, and the configuration enforcing them; evidence of secure storage, such as hashing configuration for stored credentials and a controlled vault for shared or privileged secrets
Common gap: Policies exist but not enforced
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.5 Secure authentication

Implement authentication technologies and procedures based on access restrictions and policy.

What the ISO 27002 guidance expects the document to say: Requires secure authentication technologies and procedures to be implemented, driven by the information access restrictions and the topic specific policy on access control.

Evidence an auditor accepts: The authentication standard, setting required methods against the sensitivity of the information and the access route; configuration evidence per system showing the enforced authentication, including multi factor coverage and the factors accepted; evidence of protection against brute force and credential stuffing, such as lockout, rate limiting and anomaly detection
Common gap: Reliance on static passwords only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 A.3.23 Secure authentication

Where required by the customer, the organization shall provide the capability for secure log-on procedures for any user accounts under the customer's control, in addition to applying secure authentication to its own accounts on systems that process PII.

Evidence an auditor accepts: Secure authentication capabilities offered for customer-controlled accounts and evidence customers can enable them; authentication configuration on the organization's own accounts on PII systems; contract or service description recording the capability
Common gap: Customer accounts limited to password-only log-on with no stronger option
Source: ISO/IEC 27701:2025

The NIS2 Directive

NIS2 Art. 21(2)(j) Multi-factor or continuous authentication, secured communications and secured emergency communications

This point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always coverage: remote access, administrative access, and access to the systems behind the essential service are where absence matters most. Secured voice, video and text communications within the entity is the second limb. The third, secured emergency communication systems, is the one most often absent, and it is the one that decides whether the entity can coordinate during an incident in which its normal collaboration and directory services are unavailable or untrusted. A crisis plan that runs on the corporate messaging platform does not satisfy this if that platform is what has been compromised.

Evidence an auditor accepts: Coverage report for multi-factor or continuous authentication across remote, privileged and essential-service access; the reasoning and compensating controls for any access path left without it; configuration evidence for secured voice, video and text communications within the entity
Common gap: Multi-factor authentication on the corporate portal but not on administrative or machine access paths
Source: NIS2 Directive

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Identity and access management standard · Privileged access management policy