SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Storage of password

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Storage of password

What the ISO 27001 says about protection and storage of passwords, for example I have the passwords of a very sensitive server of the company and have to leave stored somewhere if someday I'm not available. The standard requires some action to it?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 12, 2016

There are some security controls related to the protection and storage of passwords:

9.3.1 Use of secret authentication information: Regarding to your question, here is important to ensure proper protection of passwords when passwords are used as secret authentication information in automated log-on procedures and are stored.
9.4.3 Password management system: Regarding to your question, here is important to store and transmit passwords in protected form.

What is my recommendation? Use a software as a password management system, and store your password there. Also can be interesting that another people of your organization (closer to you) have access to this software.
Anyway, please remember what is the list of mandatory documents reading this article “List of mandatory documents required by ISO 27001 (2013 revision)” : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/

Quote
0 0
Guest
Guest post Jan 12, 2016

Save the password in a safe and let responsible people for this information are recommended?
Or let part of the password in one place and another part elsewhere is advisable?
Or do you only recommend the use of software?

Quote
0 0
Guest
AntonioS Jan 12, 2016

For me the best option is the software, because is more easy and confortable to manage the ISMS. Anyway, others options can be good for the ISO 27001, the standard not says how you need to manage passwords in a specific way

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Feb 28, 2022 ISO 27001 & 22301
Replies: 1
0 0

Software Password Storage

Guest user Created:   Jun 09, 2018 ISO 27001 & 22301
Replies: 1
0 0

BYOD Policy