Security Questionnaire Mapper
Access and identity ยท question family

Password policy: the clause the question tests

What the password rules are and where they are enforced.

How the customer usually asks it

example

"Do you have a password policy that sets minimum length and complexity?"

Read this question

Anchor clauses

4 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.17 Authentication information
SOC 2 (Trust Services Criteria)CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
SIG (Shared Assessments)domain H Access Control
CSA Cloud Controls Matrix v4.0.1IAM-02 Strong Password Policy and Procedures

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The password standard (length, complexity, reuse, lockout) and the system settings that enforce it.

The clauses, with what an assessor asks for

ISO 27001 5.17 Authentication information

Control allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.

Evidence an assessor expects: Password policy; Secret inventory; User training records; Access review logs
Where answers usually fall short: Policies exist but not enforced; No centralized inventory of secrets
Source: ISO/IEC 27001:2022
SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Inventory of information assets with classification and owner; Access control software configuration and the rule sets that enforce it; Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software; Network segmentation design with firewall or ACL rule review evidence; Register of points of access used by outside entities and the data that flows through each
Where answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
Source: SOC 2 (Trust Services Criteria)
SIG domain H Access Control

What it asks for, in one line (the standard's own text is not quoted here):

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Evidence an assessor expects: Access management policy; User access review reports; Privileged access management tool logs; Joiner mover leaver workflows
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
CSA CCM IAM-02 Strong Password Policy and Procedures

What it asks for, in one line (the standard's own text is not quoted here):

Keep an approved password policy that sets strength requirements, implement it in the systems it governs, and review it at least annually.

Evidence an assessor expects: The approved password policy with its strength requirements; Technical configuration enforcing the policy per system; Annual review record; Exception records where a system cannot enforce the policy
Where answers usually fall short: Policy strength requirements not enforceable in some systems and no exception recorded; Policy stated in words with no configuration evidence
Source: CSA Cloud Controls Matrix v4.0.1

Other families in access and identity