ISO/IEC 27001:2022 Annex A · Control 8.5
Secure Authentication: A Practical Implementation Guide
Use authentication methods that match access risk and resist common compromise paths.
This control concerns implementing secure authentication technologies and procedures based on access restrictions and policy.
What should the control achieve?
- Authentication strength matches risk.
- MFA protects sensitive and remote access.
- Credentials and sessions resist attack.
- Recovery and enrollment verify identity securely.
Step-by-step implementation
Classify authentication risk
Consider privilege, data, remote access, transaction value and threat.
Choose strong methods
Prefer phishing-resistant MFA for high-risk access and modern protocols.
Secure enrollment
Verify identity and bind factors through controlled processes.
Protect sessions
Use secure cookies, reauthentication, timeout and revocation.
Harden recovery
Apply strong verification and notify users of factor changes.
Monitor attacks
Detect brute force, impossible travel, MFA fatigue and unusual recovery.
What this could look like in practice
Administrators use hardware security keys; workforce applications use MFA and SSO. Factor replacement requires verified identity and sends an independent alert. High-risk sessions expire quickly.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Enrollment | Verified worker registers approved factors. | Enrollment log |
| Login | Risk-based policy requires MFA. | Authentication log |
| Recovery | Helpdesk verifies identity and records factor reset. | Reset ticket |
| Attack | Repeated prompts trigger blocking and investigation. | Alert record |
Implementation evidence
- Authentication standard
- Risk tiers
- MFA coverage
- Identity-proofing procedure
- Session settings
- Recovery records
- Authentication logs
- Attack detections
Useful metrics
- Sensitive accounts with MFA
- Phishing-resistant factor adoption
- Authentication attacks blocked
- Recovery events reviewed
Common mistakes
- Using SMS for highest-risk access when stronger options exist.
- Weak helpdesk recovery.
- Long-lived sessions after role change.
- Allowing legacy protocols.
- Overwhelming users with uncontrolled MFA prompts.
Questions an auditor may ask
- How is authentication strength selected?
- Which access uses phishing-resistant MFA?
- Show a factor recovery.
- How are sessions revoked?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.