Posts

Showing posts with the label Secret Authentication

ISO 27001 Annex : A.9.3 User Responsibilities

Image
ISO 27001 Annex : A.9.3 User Responsibilities  Its objective is  the Responsibility of users for safeguarding their authentication information. A.9.3.1 Use of Secret Authentication Information Control-  Use of secret authentication information should be allowed for users to follow the organization’s practices. Implementation Guidance-  It is recommended that all users: maintain confidential information on  secure authentication  to ensure that it is not leaked to the other parties, including people of authority; Avoid maintaining a record of confidential authentication details (e.g. on a document, software file or mobile device) unless it can be stored safely and the storage system (e.g. password vault) has been approved; Change details regarding secret authentication where potential  vulnerability   signs exist; When passwords are used as secret authentication information, select quality passwords with a minimum length of: – ...