HomeControl Library › 3.5.10
3.5 Identification & Authentication5 pts

3.5.10 — Protect stored and transmitted passwords

Store and transmit only cryptographically-protected passwords.

Passwords are always cryptographically protected — never plain text.

What it actually means

Passwords must be hashed at rest and protected (TLS) in transit — never stored or sent in plain text. A managed identity provider does this automatically; the risk is almost always a homegrown app, script, spreadsheet, or config file holding credentials in the clear.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library