Question group
Access and identity
Who can reach the customer's data and how they prove who they are: multi-factor authentication, passwords, access reviews and privileged accounts. The section where the same question is most often asked twice in different words.
The families
4 families| Family and a typical question | ISO 27001 | Evidence expected |
|---|---|---|
| Multi-factor authenticationIs multi-factor authentication enforced for all remote access? | 8.5 | Configuration evidence showing which systems require a second factor, which users it covers, and the exceptions with their reason. |
| Password policyDo you have a password policy that sets minimum length and complexity? | 5.17 | The password standard (length, complexity, reuse, lockout) and the system settings that enforce it. |
| Access provisioning and reviewHow often are user access rights reviewed, and by whom? | 5.18 | The access request and approval records, the last completed access review with its sign-off, and leaver records showing when access was removed. |
| Privileged accessHow is privileged or administrator access restricted and monitored? | 8.2 | The list of privileged accounts with owners, how privileged sessions are granted and logged, and the last review of that list. |