Cyber Resilience

← ISO 27001 Annex A

A.8.5 Technological

Secure authentication

AttributesPreventiveC·I·AProtectIdentity and access managementProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (25)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (18)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (15)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (137)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (1076)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.002←MT1001.003←MT1003→MT1003.001→PT1003.002→MT1003.003→PT1003.004→PT1003.005→MT1003.006←M →PT1003.007←M →PT1003.008→MT1006←MT1008←MT1014←MT1021→MT1021.001→MT1021.002→MT1021.003→MT1021.004→MT1021.005→MT1021.006→MT1021.007→MT1021.008→MT1027.001←MT1027.006←MT1027.008←MT1027.010←MT1027.014←MT1027.018←MT1036←MT1036.002←MT1036.003←MT1036.004←MT1036.005←MT1036.007←MT1036.008←MT1036.009←MT1036.010←MT1036.012←MT1037→MT1037.001→PT1037.002←M →PT1037.003→MT1037.004→PT1040→MT1047→PT1053←P →MT1053.002←P →MT1053.003→PT1053.005←P →PT1055←M →PT1055.001←M →PT1055.002←M →PT1055.003←M →PT1055.004←M →PT1055.005←MT1055.008←MT1055.009←M →PT1055.011←MT1055.012←MT1055.013←MT1055.014←M →PT1055.015←M →PT1056→MT1056.001→MT1056.002→MT1056.003→MT1056.004→MT1059→PT1059.002→PT1059.004→PT1059.007→PT1059.008←P →MT1059.009←M →MT1059.012→PT1059.013→PT1068←MT1069.003→MT1070←MT1071←MT1071.001←MT1071.002←MT1071.004←M →PT1072→MT1078→PT1078.001→MT1078.002→MT1078.003→MT1078.004→MT1087→PT1087.003→MT1087.004→MT1090←MT1090.002←MT1090.003←MT1090.004←MT1095←MT1098→MT1098.001→MT1098.002←P →MT1098.003←P →MT1098.004→MT1098.005→MT1098.006→PT1098.007←P →PT1102←MT1102.001←MT1102.002←MT1102.003←MT1104←MT1106←MT1110→MT1110.001→MT1110.002→MT1110.003→MT1110.004→MT1111→MT1114.002→MT1114.003→MT1123→PT1127←MT1127.001←M →PT1127.002→PT1127.003←PT1132.001←PT1132.002←PT1133→MT1134→PT1134.001→PT1134.002→PT1134.003→MT1134.005←M →PT1136→MT1136.001←PT1136.002←MT1136.003→MT1137→MT1137.001→PT1137.002→PT1137.003→PT1137.004→PT1137.005←M →PT1137.006→PT1176←M →PT1176.001←M →PT1185→PT1187→MT1189←M →PT1190←M →PT1199→PT1200←PT1201→MT1202←PT1204→PT1204.001←M →PT1204.002←M →PT1204.003←MT1204.004←M →PT1205←MT1205.001←M →PT1207←MT1210→PT1211←PT1212→MT1213←P →PT1213.001→MT1213.002→MT1213.003←P →MT1213.004→PT1213.006←P →PT1216←M →PT1216.001←MT1216.002←M →PT1218←MT1218.002←MT1218.003←P →PT1218.004←M →MT1218.005←M →PT1218.007←M →PT1218.008←M →PT1218.009←MT1218.010←M →PT1218.011←MT1218.012←M →PT1218.013←M →PT1218.014→PT1219→MT1219.001←M →PT1219.002→PT1219.003←M →PT1220←PT1221→PT1222←PT1222.001←PT1222.002←MT1480.001←MT1484→PT1484.001←PT1484.002→PT1496.004→MT1497←PT1499←PT1505.003←M →PT1505.005←M →PT1528→MT1529→PT1530→MT1531←P →PT1534→PT1535←MT1537←M →PT1538→MT1539→MT1542.001←MT1542.002←MT1542.003←MT1543.001←MT1543.005→PT1546→PT1546.002→PT1546.003←M →PT1546.007→PT1546.008→PT1546.011←PT1546.012←P →PT1546.014→PT1546.015→PT1546.016→PT1547→PT1547.001←P →PT1547.002←P →PT1547.004→PT1547.005→PT1547.008←PT1547.012→PT1547.014→PT1547.015←M →PT1548→MT1548.001←PT1548.002←P →PT1548.003→MT1548.004→PT1548.005→PT1548.006←M →PT1550→MT1550.001→MT1550.002→MT1550.003→MT1550.004→MT1552→PT1552.001→PT1552.004→PT1552.005←M →PT1552.006→PT1552.007→MT1552.008→PT1553←P →PT1553.001←MT1553.002←MT1553.003←MT1553.004←M →PT1553.005←MT1553.006←M →PT1554←PT1555→MT1555.001→MT1555.002→PT1555.003→MT1555.004→MT1555.005→MT1555.006→MT1556→MT1556.001→PT1556.002→PT1556.003→MT1556.005→PT1556.006→MT1556.007→PT1556.008→PT1556.009→MT1557→MT1557.001→MT1557.002←MT1557.003←PT1557.004→PT1558→MT1558.001→MT1558.002→MT1558.003→MT1558.004→MT1558.005→MT1559.001→PT1563→PT1563.001→PT1563.002→MT1564.002→PT1564.004←PT1566→MT1566.001→PT1566.002→MT1566.003←M →PT1566.004→PT1568←PT1569→PT1569.001→PT1569.003→PT1571←MT1572←MT1573←MT1574←M →PT1574.001←M →PT1574.004←MT1574.006←PT1574.008←PT1574.010←PT1574.012←PT1574.013←M →PT1578←M →PT1578.001←MT1578.002←MT1578.003←PT1578.004←MT1578.005←PT1580→MT1583.007←MT1584←MT1584.001←M →MT1584.005→PT1584.006←P →PT1584.007←MT1584.008←PT1585.001←PT1585.002←PT1585.003←MT1586→MT1586.001→MT1586.002→MT1586.003→MT1587.002→MT1587.003←P →MT1588.003→PT1588.004←P →PT1588.005←PT1589→MT1589.001→MT1589.002←PT1595.003→PT1598→MT1598.001→PT1598.002←MT1598.003→MT1598.004←P →PT1599←MT1599.001←PT1600←PT1600.001←PT1601←PT1601.001←PT1601.002←MT1602.001→PT1602.002→PT1606→MT1606.001→MT1606.002→MT1608.005→MT1611←PT1620←MT1621→MT1622←PT1649→MT1650←MT1651→MT1657←P →PT1666←PT1669←P →PT1671→PT1674←P →PT1683.002←PT1684→MT1684.001→PT1684.002→MT1685←MT1685.001←MT1685.002←MT1685.003←MT1685.004←MT1685.005←MT1685.006←MT1686←FT1686.001←MT1686.003←MT1687←PT1688←MT1689→PT1690←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (16)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.