Cyber Insurance Subjectivity Tracker

Controls / Multi-factor authentication

Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: offer or require multi-factor sign-in for customers on any online service you run that holds their sensitive data.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1681
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1681 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Customer authentication flow showing a second factor for services holding sensitive customer data; Customer enrolment statistics

ISM-1892
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1892 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration of multi-factor authentication for staff access to the organisation's online customer services; Access review of staff accounts on customer service platforms

ISM-1893
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1893 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Multi-factor settings for staff accounts on third-party customer service platforms; Vendor attestation or admin console export showing enforcement

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1873
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option. Required at Maturity Level Two of the Multi-factor authentication mitigation strategy (Appendix B); ISM control ISM-1873 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1874 (phishing-resistant multi-factor authentication for customers).

evidence an assessor asks for Customer authentication options showing a phishing-resistant option is offered; Customer help material describing the option

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 6.3
CIS Controls v8.1
Require MFA for Externally-Exposed Applications

Where supported, make every enterprise or third-party application exposed externally enforce MFA. Enforcing MFA via an SSO provider or a directory service is an acceptable way to meet this Safeguard.

evidence an assessor asks for SSO or application MFA configuration for all externally exposed applications; List of external applications with MFA status and any exceptions; Authentication standard requiring MFA on every internet-facing enterprise and third-party application; SSO conditional access policy export showing MFA required for external sign-ins to each listed application; Sign-in log sample for external apps showing MFA challenge satisfied, with legacy authentication attempts blocked

PR.AA-03
NIST CSF 2.0

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.5
ISO/IEC 27001:2022 (lens)

Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5.

evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 30 by the default rule (multi-factor authentication), unless it is marked not sure (day 90). The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule