logo

Passwords to passkeys: Staying ISO 27001 compliant in a passwordless era

ID: db50e56c-8a06-5d9d-909f-fedb0f94af0b

STIX ID: report--db50e56c-8a06-5d9d-909f-fedb0f94af0b

Feed Name: Bleeping Computer

Date Published: 2026-02-16

Date Updated: 2026-04-20

Author: Sponsored by Passwork

...
...

This sponsored guide advocates transitioning from passwords to passkeys using FIDO2/WebAuthn, explains how passkeys meet NIST AAL2/AAL3, and maps the approach to ISO/IEC 27001 controls (A 5.15, A 5.17, A 8.5), including risk assessment, fallback and recovery planning, and monitoring for threats like downgrade attacks; it highlights benefits (eliminating password-based attacks, faster sign-ins, reduced support costs), addresses challenges in mixed environments, and provides best practices for phased, compliant implementation—concluding with a promotion of Passwork’s enterprise features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.