graphgrc

SCF - IAC-18 - User Responsibilities for Account Management

Mechanisms exist to compel users to follow accepted practices in the use of authentication mechanisms (e.g., passwords, passphrases, physical or logical security tokens, smart cards, certificates, etc.).

Mapped framework controls

ISO 27002

NIST 800-53

Control questions

Does the organization compel users to follow accepted practices in the use of authentication mechanisms (e?g?, passwords, passphrases, physical or logical security tokens, smart cards, certificates, etc?)?