Cyber Insurance Subjectivity Tracker

Controls / Multi-factor authentication

The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: move staff sign-in to phishing-resistant multi-factor authentication (security keys or passkeys).

In Australia

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1682
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating users of systems is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1682 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration requiring phishing-resistant multi-factor authentication for users of systems; Enrolment report for security keys or platform authenticators

ISM-1872
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating users of online services is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1872 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy requiring phishing-resistant methods (for example FIDO2 or certificate-based) for users of online services; Sign-in logs showing only phishing-resistant methods succeed

In the United States

No requirement in the core list for the United States covers this control; it is on the schedule as a condition beyond the core list.

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-AC.8
Cyber Essentials
Passwordless Authentication

Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the account.

evidence an assessor asks for list of accounts using passwordless authentication and the method in use; authenticator registration and revocation records; policy statement covering accepted passwordless methods

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.5
ISO/IEC 27001:2022 (lens)

Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5.

evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 30 by the default rule (multi-factor authentication), unless it is marked not sure (day 90). The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule