Compliance
KeyCare Pass and ISO/IEC 27001
If your organization runs an ISO/IEC 27001 information security management system, KeyCare Pass can support several Annex A controls about access and authentication.
Prices and options by email
How to get started today
KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.
What ISO 27001 asks for
ISO/IEC 27001:2022 specifies the requirements for an information security management system (ISMS). Annex A lists 93 reference controls; an organization chooses the ones that apply in its Statement of Applicability.
Certification applies to your ISMS, through an accredited certification body. KeyCare Pass itself is not ISO/IEC 27001 certified.
Where KeyCare Pass fits
Annex A controls (2022 edition) where KeyCare Pass can be part of your implementation.
| What is asked for | How KeyCare Pass can help | Plans |
|---|---|---|
| 5.15 Access control | Collections, groups, five permission levels and roles put access rules into practice. | Teams, Enterprise |
| 5.16 Identity management | One account per person; invite, confirm with fingerprint phrases, revoke and remove members. | Teams, Enterprise |
| 5.17 Authentication information | Generated passwords and passphrases, master password requirements, and encrypted storage of secrets. | All plans; policies on Enterprise |
| 5.18 Access rights | See who can reach each collection and remove access when people change roles or leave. | Teams, Enterprise |
| 8.2 Privileged access rights | Separate owner, admin and custom roles; the Manage collection permission for collection owners. | Custom roles on Enterprise |
| 8.5 Secure authentication | Require two-step login; FIDO2 security keys and passkeys. | Policy: Enterprise |
| 8.15 Logging | Event logs of item, collection, member and policy activity, and sign-ins, with IP addresses. | Teams, Enterprise |
| 8.24 Use of cryptography | Vault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS. | All plans |
What stays with you
A password manager is one control among many. These remain your organization's work:
- The ISMS itself: scope, risk assessment, Statement of Applicability
- Supplier assessment of GovPAM and the hosting providers
- Regular access reviews, using the information KeyCare Pass shows
- Keeping evidence: export event logs through the API as your process requires
Frequently asked questions
Can you send us your ISO certificate?
KeyCare Pass does not hold an ISO/IEC 27001 certificate. We can answer security questionnaires about its design and hosting.
Can we keep event logs for longer?
Owners and admins can read event logs in the Admin Console and collect them with the public API into your own log store.
Need details for your auditor?
Ask us about KeyCare Pass's design, hosting and data handling.