Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
98 controls
03.01.01
Account management
Access control
3 evidence1 control
03.01.02
Access enforcement
Access control
2 evidence1 control
03.01.03
Information flow enforcement
Access control
2 evidence1 control
03.01.04
Separation of duties
Access control
3 evidence1 control
03.01.05
Least privilege
Access control
2 evidence1 control
03.01.06
Least privilege - privileged accounts
Access control
3 evidence1 control
03.01.07
Least privilege - privileged functions
Access control
2 evidence1 control
03.01.08
Unsuccessful logon attempts
Access control
2 evidence1 control
03.01.09
System use notification
Access control
2 evidence1 control
03.01.10
Device lock
Access control
2 evidence1 control
03.01.11
Session termination
Access control
2 evidence1 control
03.01.12
Remote access
Access control
3 evidence1 control
03.01.16
Wireless access
Access control
2 evidence1 control
03.01.18
Access control for mobile devices
Access control
3 evidence1 control
03.01.20
Use of external systems
Access control
2 evidence1 control
03.01.22
Publicly accessible content
Access control
3 evidence1 control
03.02.01
Literacy training and awareness
Awareness and training
3 evidence1 control
03.02.02
Role-based training
Awareness and training
2 evidence1 control
03.03.01
Event logging
Audit and accountability
3 evidence1 control
03.03.02
Audit record content
Audit and accountability
2 evidence1 control
03.03.03
Audit record generation
Audit and accountability
2 evidence1 control
03.03.04
Response to audit logging process failures
Audit and accountability
2 evidence1 control
03.03.05
Audit record review, analysis, and reporting
Audit and accountability
3 evidence1 control
03.03.06
Audit record reduction and report generation
Audit and accountability
2 evidence1 control
03.03.07
Time stamps
Audit and accountability
2 evidence1 control
03.03.08
Protection of audit information
Audit and accountability
3 evidence1 control
03.04.01
Baseline configuration
Configuration management
2 evidence1 control
03.04.02
Configuration settings
Configuration management
2 evidence1 control
03.04.03
Configuration change control
Configuration management
3 evidence1 control
03.04.04
Impact analyses
Configuration management
2 evidence1 control
03.04.05
Access restrictions for change
Configuration management
2 evidence1 control
03.04.06
Least functionality
Configuration management
2 evidence1 control
03.04.08
Authorized software - allow by exception
Configuration management
2 evidence1 control
03.04.10
System component inventory
Configuration management
2 evidence1 control
03.04.11
Information location
Configuration management
2 evidence1 control
03.04.12
System and component configuration for high-risk areas
Configuration management
2 evidence1 control
03.05.01
User identification, authentication, and re-authentication
Identification and authentication
2 evidence1 control
03.05.02
Device identification and authentication
Identification and authentication
2 evidence1 control
03.05.03
Multi-factor authentication
Identification and authentication
3 evidence1 control
03.05.04
Replay-resistant authentication
Identification and authentication
2 evidence1 control
03.05.05
Identifier management
Identification and authentication
2 evidence1 control
03.05.07
Password management
Identification and authentication
3 evidence1 control
03.05.11
Authentication feedback
Identification and authentication
2 evidence1 control
03.05.12Authenticator managementITSP.10.171Identification and authentication
Official Requirement
A. Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. B. Establish initial authenticator content for any authenticators issued by the organization. C. Establish and implement administrative procedures for initial authenticator distribution, for lost, compromised, or damaged authenticators, and for revoking authenticators. D. Change default authenticators at first use. E. Change or refresh authenticators [Assignment: organization-defined frequency] or when the following events occur: [Assignment: organization-defined events]. F. Protect authenticator content from unauthorized disclosure and modification.
Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3
In Plain English
Manage the full lifecycle of authenticators (passwords, tokens, certificates, security keys). Verify identity before issuing them, change all defaults before first use, establish procedures for lost or compromised authenticators, refresh them periodically, and protect them from unauthorized access at all times.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Authenticator lifecycle management
Implementation Steps
Verify user identity through an established process (government ID, video call, in-person verification) before issuing initial credentials or MFA devices
Force password change on first login and MFA enrollment within a defined timeframe; change all default credentials on new systems before deployment
Establish and document a self-service process for reporting lost, compromised, or damaged authenticators (MFA tokens, security keys) with immediate revocation capability
Protect authenticator storage (password vaults, certificate stores, token databases) with encryption and restricted access
Tools / Systems
IdP with initial credential workflows (temporary passwords, enrollment links)MFA token management (YubiKey Manager, IdP MFA admin)Password manager (1Password, Bitwarden) for service account credentialsCertificate management (PKI, Let's Encrypt, AWS ACM)
Typical Control Authenticator lifecycle management
Evidence Artifacts
Identity verification procedures for authenticator distribution
MFA token inventory and issuance/revocation log
Evidence that default credentials were changed before first use on recent deployments
📅Per-event for issuance/revocation; quarterly authenticator inventory review
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
03.06.01
Incident handling
Incident response
3 evidence1 control
03.06.02
Incident monitoring, reporting, and response assistance
Incident response
3 evidence1 control
03.06.03
Incident response testing
Incident response
2 evidence1 control
03.06.04
Incident response training
Incident response
2 evidence1 control
03.06.05
Incident response plan
Incident response
3 evidence1 control
03.07.04
Maintenance tools
Maintenance
3 evidence1 control
03.07.05
Non-local maintenance
Maintenance
3 evidence1 control
03.07.06
Maintenance personnel
Maintenance
4 evidence1 control
03.08.01
Media storage
Media protection
3 evidence1 control
03.08.02
Media access
Media protection
3 evidence1 control
03.08.03
Media sanitization
Media protection
3 evidence1 control
03.08.04
Media marking
Media protection
3 evidence1 control
03.08.05
Media transport
Media protection
3 evidence1 control
03.08.07
Media use
Media protection
3 evidence1 control
03.08.09
System backup - cryptographic protection
Media protection
3 evidence1 control
03.09.01
Personnel screening
Personnel security
3 evidence1 control
03.09.02
Personnel termination and transfer
Personnel security
3 evidence1 control
03.10.01
Physical access authorizations
Physical protection
3 evidence1 control
03.10.02
Monitoring physical access
Physical protection
3 evidence1 control
03.10.06
Alternate work site
Physical protection
3 evidence1 control
03.10.07
Physical access control
Physical protection
3 evidence1 control
03.10.08
Access control for transmission
Physical protection
3 evidence1 control
03.11.01
Risk assessment
Risk assessment
3 evidence1 control
03.11.02
Vulnerability monitoring and scanning
Risk assessment
3 evidence1 control
03.11.04
Risk response
Risk assessment
3 evidence1 control
03.12.01
Security assessment
Security assessment and monitoring
3 evidence1 control
03.12.02
Plan of action and milestones
Security assessment and monitoring
3 evidence1 control
03.12.03
Continuous monitoring
Security assessment and monitoring
3 evidence1 control
03.12.05
Information exchange
Security assessment and monitoring
3 evidence1 control
03.13.01
Boundary protection
System and communications protection
3 evidence1 control
03.13.04
Information in shared system resources
System and communications protection
3 evidence1 control
03.13.06
Network communications - deny by default - allow by exception
System and communications protection
3 evidence1 control
03.13.08
Transmission and storage confidentiality
System and communications protection
3 evidence1 control
03.13.09
Network disconnect
System and communications protection
3 evidence1 control
03.13.10
Cryptographic key establishment and management
System and communications protection
3 evidence1 control
03.13.11
Cryptographic protection
System and communications protection
3 evidence1 control
03.13.12
Collaborative computing devices and applications
System and communications protection
3 evidence1 control
03.13.13
Mobile code
System and communications protection
3 evidence1 control
03.13.15
Session authenticity
System and communications protection
3 evidence1 control
03.14.01
Flaw remediation
System and information integrity
3 evidence1 control
03.14.02
Malicious code protection
System and information integrity
3 evidence1 control
03.14.03
Security alerts, advisories, and directives
System and information integrity
3 evidence1 control
03.14.06
System monitoring
System and information integrity
3 evidence1 control
03.14.08
Information management and retention
System and information integrity
3 evidence1 control
03.14.09
Dedicated administration workstation
System and information integrity
3 evidence1 control
03.15.01
Policy and procedures
Planning
3 evidence1 control
03.15.02
System security plan
Planning
3 evidence1 control
03.15.03
Rules of behaviour
Planning
3 evidence1 control
03.16.01
Security engineering principles
System and services acquisition
3 evidence1 control
03.16.02
Unsupported system components
System and services acquisition
3 evidence1 control
03.16.03
External system services
System and services acquisition
3 evidence1 control
03.17.01
Supply chain risk management plan
Supply chain risk management
3 evidence1 control
03.17.02
Acquisition strategies, tools, and methods
Supply chain risk management
3 evidence1 control
03.17.03
Supply chain requirements and processes
Supply chain risk management
3 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Authenticator lifecycle management
Implementation steps
Verify identity in person or through a documented verification process before distributing initial credentials or hardware tokens
Set all initial passwords as temporary and force change at first logon; replace all vendor default passwords before deployment
Maintain procedures for revoking and reissuing authenticators when lost, stolen, or compromised; log all such events
Store master credential lists and certificate private keys in encrypted vaults with access restricted to authorized personnel
Tools / systems
Active Directory (initial password and force-change settings)