6. Password or key not changed within the period, or never
A credential that is never changed stays usable for as long as anyone who ever knew it. The period is the one you set; with PCI DSS ticked, a person's password used alone reads against the 90 days of 8.3.9, and a system account against your targeted risk analysis under 8.6.3.
The rule it applies
The last changed date is more than the period you set (default 365 days) before the as-at date, or the list says never. With PCI DSS ticked, a user account whose MFA does not read yes also fires at more than 90 days (8.3.9); with MFA not recorded that line is a question. For a system account under PCI DSS 8.6.3 the period is your targeted risk analysis, and the one you set stands in for it.
A question for the account owner
When was this credential last changed, and who knows it?
Clauses
6 across the regimes you tick| Regime | Clause | Read on |
|---|---|---|
| ISO/IEC 27001 | ISO/IEC 27001 A.5.17 Authentication information | every account type |
| NIST SP 800-53 | NIST SP 800-53 IA-5 Authenticator Management | every account type |
| PCI DSS | PCI DSS 8.3.9 Single-factor passwords changed every 90 days or dynamic analysis | user accounts whose MFA does not read yes |
| ISO/IEC 27001 | ISO/IEC 27001 A.8.5 Secure authentication | user accounts whose MFA does not read yes |
| NIS2 | NIS2 Art. 21(2)(j) Multi-factor or continuous authentication, secured communications and secured emergency communications | user accounts whose MFA does not read yes |
| PCI DSS | PCI DSS 8.6.3 System account passwords protected against misuse | application and system accounts only |
The first clause, set out
ISO/IEC 27001 A.5.17Authentication informationA management process is to control how authentication information is allocated and managed, and it includes telling personnel how to handle such information properly. Purpose (stated in ISO/IEC 27002:2022): ensures proper entity authentication and prevents authentication process failures. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.17.