Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.05.07Password managementITSP.10.171Identification and authentication

Official Requirement

A. Maintain a list of commonly used, expected, or compromised passwords and update the list [Assignment: organization-defined frequency] and when organizational passwords are suspected to have been compromised. B. Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords. C. Transmit passwords only over cryptographically protected channels. D. Store passwords in a cryptographically protected form. E. Select a new password upon first use after account recovery. F. Enforce the following composition and complexity rules for passwords: [Assignment: organization-defined composition and complexity rules].

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Passwords must be checked against a list of known-compromised and commonly used passwords. They must be transmitted only over encrypted channels and stored using strong, salted hashing. Set minimum length requirements (15 characters without MFA, or 8 characters with MFA). If a password recovery is triggered, force a new password. Rotate passwords periodically if MFA is not used.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Password policy and compromised password prevention

Implementation steps

  1. Deploy a password filter (e.g., Specops Password Policy, Lithnet Password Protection for AD) that checks passwords against compromised lists
  2. Configure Active Directory password policy with minimum length and complexity requirements via Group Policy
  3. Ensure LDAP is configured with LDAPS (TLS) for all password transmissions; disable plaintext LDAP binds
  4. Configure password recovery to force new password creation and set periodic rotation intervals if MFA is not deployed

Tools / systems

Evidence artifacts

Evidence frequency: Continuous enforcement; quarterly compromised list update; annual policy review