Proper and secure authentication procedures are the backbone of most general and topic-specific access policies, whether they relate to PII or information, assets and data in general.
Easily guessable and poorly constructed passwords are low hanging fruit for would-be cybercriminals seeking to gain access to an organisation’s PII, which is usually either ransomed back, used as reputational fodder or sold on the dark web to the highest bidder.
Users need to adhered to a strictly-enforced password policy that covers off generation, distribution, password construction and makes use of available authentication technology (SSO, password vaults).
ISO 27702 6.6.3 features just one sub clause, which contains amalgamated guidance from ISO 27002 that outlines how organisations should approach authentication security:
There are no UK GDPR citations to consider, nor do ISO provide any PIMS or PII-specific guidance points to adhere to.
Authentication details should be distributed and managed so that:
Any personnel who uses organisational authentication information should ensure that:
Organisations should consider implementing a password management system (specialised password control applications) that:
To safeguard PII and improve organisational privacy protection efforts, passwords should follow four guiding principles:
Organisations should also consider the use of authentication protocols such as Single Sign-On (SSO) to improve password security, but such measures should only be considered alongside the organisations unique technical and operational requirements.
Book a tailored hands-on session
based on your needs and goals
Book your demo
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27002 Control | Associated GDPR Articles |
---|---|---|---|
6.6.3.1 | Use of Secret Authentication Information | 5.17 – Authentication Information for ISO 27002 | None |
How do we help?
By adding a PIMS to your ISMS on the ISMS.online platform, your security posture remains all-in-one-place and you’ll avoid duplication where the standards overlap.
With your PIMS instantly accessible to interested parties, it’s never been easier to monitor, report and audit against both ISO 27002 and ISO 27701 at the click of a button.
All the features you need:
Find out how much time and money you’ll save on your journey to a combined ISO 27002 and 27701 certification using ISMS.online by booking a demo.
ISMS.online is a
one-stop solution that radically speeded up our implementation.
We can’t think of any company whose service can hold a candle to ISMS.online.