Password policy: the clause the question tests
What the password rules are and where they are enforced.
How the customer usually asks it
example"Do you have a password policy that sets minimum length and complexity?"
Anchor clauses
4 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 5.17 Authentication information |
| SOC 2 (Trust Services Criteria) | CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets |
| SIG (Shared Assessments) | domain H Access Control |
| CSA Cloud Controls Matrix v4.0.1 | IAM-02 Strong Password Policy and Procedures |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
The password standard (length, complexity, reuse, lockout) and the system settings that enforce it.
The clauses, with what an assessor asks for
ISO 27001 5.17 Authentication informationControl allocation and handling of passwords, keys and other authentication secrets, and advise users on good practice.
Where answers usually fall short: Policies exist but not enforced; No centralized inventory of secrets
Source: ISO/IEC 27001:2022
SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assetsNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
Source: SOC 2 (Trust Services Criteria)
SIG domain H Access ControlWhat it asks for, in one line (the standard's own text is not quoted here):
Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
CSA CCM IAM-02 Strong Password Policy and ProceduresWhat it asks for, in one line (the standard's own text is not quoted here):
Keep an approved password policy that sets strength requirements, implement it in the systems it governs, and review it at least annually.
Where answers usually fall short: Policy strength requirements not enforceable in some systems and no exception recorded; Policy stated in words with no configuration evidence
Source: CSA Cloud Controls Matrix v4.0.1