ISO/IEC 27001:2022 Annex A · Control 5.17
Authentication Information: A Practical Implementation Guide
Issue, store, use and reset passwords, keys, tokens and secrets without exposing them.
This control addresses allocation and management of authentication information used to prove an identity.
What should the control achieve?
- Authentication information is issued securely.
- Users understand protection duties.
- Storage and transmission reduce exposure.
- Reset and recovery verify identity appropriately.
Step-by-step implementation
Inventory credential types
Identify passwords, API keys, certificates, tokens, PINs and recovery factors.
Set issuance rules
Use unique temporary values, secure channels and forced change where relevant.
Protect storage
Use approved password managers, hashing, HSMs or secret vaults according to use.
Control disclosure
Prohibit sharing and insecure transmission; define emergency procedures.
Secure reset
Apply identity verification, event logging and notification.
Rotate and revoke
Trigger change after exposure, role change, expiry or supplier transition.
What this could look like in practice
Administrators retrieve time-limited secrets from a vault using MFA. Initial user credentials are delivered through a separate channel and must be changed. Helpdesk resets require verified identity and generate an alert to the user.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Initial credential | Unique temporary secret with forced change. | Provisioning log |
| API secret | Vaulted, scoped, rotated and owned. | Secrets inventory |
| Reset | Helpdesk verifies identity and records action. | Reset ticket and alert |
| Exposure | Credential is revoked and related activity reviewed. | Incident record |
Implementation evidence
- Authentication information policy
- Credential inventory
- Password-manager or vault configuration
- Issuance records
- Reset procedure
- Rotation logs
- Revocation records
- User guidance
Useful metrics
- Secrets outside approved vaults
- Overdue rotations
- Reset fraud or failures
- Exposed credentials revoked within target
Common mistakes
- Sending usernames and passwords together.
- Storing shared secrets in documents or code.
- Using knowledge questions for high-risk resets.
- Rotating secrets without updating dependencies safely.
- Failing to notify users of changes.
Questions an auditor may ask
- How are initial credentials delivered?
- Where are administrative and application secrets stored?
- How is identity verified during reset?
- Show response to an exposed credential.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.