Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.5

Secure Authentication: A Practical Implementation Guide

Use authentication methods that match access risk and resist common compromise paths.

This control concerns implementing secure authentication technologies and procedures based on access restrictions and policy.

Practical interpretation: Authentication security includes enrollment, factor choice, protocol, session handling, recovery, logging and user experience—not simply a password rule.

What should the control achieve?

  • Authentication strength matches risk.
  • MFA protects sensitive and remote access.
  • Credentials and sessions resist attack.
  • Recovery and enrollment verify identity securely.

Step-by-step implementation

1

Classify authentication risk

Consider privilege, data, remote access, transaction value and threat.

2

Choose strong methods

Prefer phishing-resistant MFA for high-risk access and modern protocols.

3

Secure enrollment

Verify identity and bind factors through controlled processes.

4

Protect sessions

Use secure cookies, reauthentication, timeout and revocation.

5

Harden recovery

Apply strong verification and notify users of factor changes.

6

Monitor attacks

Detect brute force, impossible travel, MFA fatigue and unusual recovery.

What this could look like in practice

Administrators use hardware security keys; workforce applications use MFA and SSO. Factor replacement requires verified identity and sends an independent alert. High-risk sessions expire quickly.

ActivityPractical implementationEvidence
EnrollmentVerified worker registers approved factors.Enrollment log
LoginRisk-based policy requires MFA.Authentication log
RecoveryHelpdesk verifies identity and records factor reset.Reset ticket
AttackRepeated prompts trigger blocking and investigation.Alert record

Implementation evidence

  • Authentication standard
  • Risk tiers
  • MFA coverage
  • Identity-proofing procedure
  • Session settings
  • Recovery records
  • Authentication logs
  • Attack detections

Useful metrics

  • Sensitive accounts with MFA
  • Phishing-resistant factor adoption
  • Authentication attacks blocked
  • Recovery events reviewed

Common mistakes

  • Using SMS for highest-risk access when stronger options exist.
  • Weak helpdesk recovery.
  • Long-lived sessions after role change.
  • Allowing legacy protocols.
  • Overwhelming users with uncontrolled MFA prompts.

Questions an auditor may ask

  • How is authentication strength selected?
  • Which access uses phishing-resistant MFA?
  • Show a factor recovery.
  • How are sessions revoked?
Implementation test: Exercise enrollment, normal login, suspicious login, lost factor and termination for a privileged user.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.