Controls for identification codes/passwords (11.300)
- Last UpdatedAug 14, 2025
- 1 minute read
Systems using a combination of identification code (e.g. user ID) and password as the electronic signature components must ensure the integrity of these signatures through a series of controls.
11.300 (a): Maintain user ID and password combinations so no two individuals can have the same combination.
11.300 (b): Codes and passwords are periodically checked or revised.
11.300 (c): Lost or potentially compromised identification devices (e.g. tokens, cards) or passwords are voided and replaced with a new equivalent.
11.300 (d): Transaction safeguards are used to prevent unauthorized use of IDs or passwords.
11.300 (e): ID or password generating devices (e.g. tokens) must be tested initially and periodically to ensure they are unaltered and function properly.