Controls / Multi-factor authentication
Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: offer or require multi-factor sign-in for customers on any online service you run that holds their sensitive data.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1681 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1681 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Customer authentication flow showing a second factor for services holding sensitive customer data; Customer enrolment statistics |
| ISM-1892 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1892 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration of multi-factor authentication for staff access to the organisation's online customer services; Access review of staff accounts on customer service platforms |
| ISM-1893 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1893 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Multi-factor settings for staff accounts on third-party customer service platforms; Vendor attestation or admin console export showing enforcement |
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1873 Essential Eight, Maturity Level Two | Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option. Required at Maturity Level Two of the Multi-factor authentication mitigation strategy (Appendix B); ISM control ISM-1873 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1874 (phishing-resistant multi-factor authentication for customers). evidence an assessor asks for Customer authentication options showing a phishing-resistant option is offered; Customer help material describing the option |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 6.3 CIS Controls v8.1 | Require MFA for Externally-Exposed Applications Where supported, make every enterprise or third-party application exposed externally enforce MFA. Enforcing MFA via an SSO provider or a directory service is an acceptable way to meet this Safeguard. evidence an assessor asks for SSO or application MFA configuration for all externally exposed applications; List of external applications with MFA status and any exceptions; Authentication standard requiring MFA on every internet-facing enterprise and third-party application; SSO conditional access policy export showing MFA required for external sign-ins to each listed application; Sign-in log sample for external apps showing MFA challenge satisfied, with legacy authentication attempts blocked |
| PR.AA-03 NIST CSF 2.0 | Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 (lens) | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 by the default rule (multi-factor authentication), unless it is marked not sure (day 90). The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.