Back to all 93 controls
Annex A 8.5
Technological
A.8.5 Secure authentication
Use secure authentication.
What good looks like
MFA, SSO, modern protocols (OIDC/SAML), defences against brute force.
Evidence an auditor will ask for
IdP config, MFA coverage, lockout policy.
Put this control into practice
Check whether your organisation already meets Annex A 8.5 with the free Gap Analysis tool, or get implementation-ready templates for every Annex A control with the Document Pack.
