Skip to content

Credential Management

What is Credential Management?

The processes and tools for securely creating, storing, distributing, rotating, and revoking user credentials throughout their lifecycle.

Information Security

What the standards actually require on credential management

Requirements naming credential management across 5 standards, quoted from the control text.

Threats to credential issuance, storage, and revocation including credential theft and compromise

29115-9.3 · Credential management threats

FIDO Client-to-Authenticator Protocol 2.1 (CTAP2.1, FIDO Alliance Proposed Standard). The protocol between the client (operating system + browser) + authenticator devices. CTAP2.1 COMMANDS: authenticatorMakeCredential (registration);

FIDO2-CTAP2.1-API · FIDO CTAP2.1 Authenticator API Commands and Credential Management

Apply strong authentication mechanisms appropriate to the criticality of the OT function, manage credentials securely, and avoid default or shared credentials where operationally feasible.

OT-IAM-2 · Authentication and Credential Management

Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management.

CIS-14.3 · Train Workforce Members on Authentication Best Practices

Questions people ask about credential management

What is Credential Management?
The processes and tools for securely creating, storing, distributing, rotating, and revoking user credentials throughout their lifecycle.
Why is Credential Management important for compliance?
Credential Management is a key concept in Information Security. Understanding credential management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Credential Management?
Credential Management appears in the requirement text of ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, FIDO2 / WebAuthn, NIST SP 800-82 Rev 3, CIS Controls v8, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2). Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Credential Management?
Explore our compliance framework pages to see how credential management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Credential Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.