ISO 27001 Annex : A.9.3 User Responsibilities
ISO 27001 Annex : A.9.3 User Responsibilities Its objective is the Responsibility of users for safeguarding their authentication information. A.9.3.1 Use of Secret Authentication Information Control- Use of secret authentication information should be allowed for users to follow the organization’s practices. Implementation Guidance- It is recommended that all users: maintain confidential information on secure authentication to ensure that it is not leaked to the other parties, including people of authority; Avoid maintaining a record of confidential authentication details (e.g. on a document, software file or mobile device) unless it can be stored safely and the storage system (e.g. password vault) has been approved; Change details regarding secret authentication where potential vulnerability signs exist; When passwords are used as secret authentication information, select quality passwords with a minimum length of: – ...