Cyber Insurance Subjectivity Tracker

Controls / Multi-factor authentication

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: turn on multi-factor sign-in for remote access and every administrator account.

In Australia

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1173
Essential Eight, Maturity Level Two

Multi-factor authentication is used to authenticate privileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1173 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enforcing multi-factor authentication for privileged users of systems, including console and remote administration; Sample of privileged sign-in logs showing the second factor

ISM-0974
Essential Eight, Maturity Level Two

Multi-factor authentication is used to authenticate unprivileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-0974 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enforcing multi-factor authentication for unprivileged users signing in to systems (workstations and remote access); Coverage report of users enrolled

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 8.4.1
PCI DSS v4.0.1 (add-on)
MFA for non-console administrative CDE access

Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone.

evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts

PCI DSS 8.4.3
PCI DSS v4.0.1 (add-on)
MFA for remote access that could reach CDE

MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network.

evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 6.4
CIS Controls v8.1

Require MFA for remote network access.

evidence an assessor asks for Inventory of remote access paths, including VPN, ZTNA, RDP gateways and vendor support tools, each mapped to its MFA enforcement point; Access control standard requiring MFA on every remote network connection, including third parties, with the approver for any exception; VPN, ZTNA or remote desktop gateway configuration requiring a second factor for every remote session; Remote access logs showing MFA outcome per session, with any single-factor connections investigated

CIS 6.5
CIS Controls v8.1
Require MFA for Administrative Access

Where supported, require MFA on every account with administrative access, on every enterprise asset, whether the asset is managed on site or by a third-party provider.

evidence an assessor asks for MFA configuration for all administrative accounts, on-site and third-party managed; Report of admin accounts with MFA enrolment status; Privileged access standard requiring MFA for all administrative logons, including provider-managed assets; PAM or identity provider policy export enforcing MFA on admin roles, cloud consoles and hypervisor management; Admin logon records sampled across on-site and hosted assets showing MFA used on each

PR.AA-03
NIST CSF 2.0

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review

FTC Safeguards Rule, when it applies

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(5)
FTC Safeguards Rule (add-on)
314.4(c)(5) Multi-factor authentication

Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.

evidence an assessor asks for MFA enforcement on every information system access, including remote and administrative access; Qualified Individual's written approval of any equivalent control

23 NYCRR 500, when it applies

Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.

ClauseThe held text, and the evidence an assessor asks for
500.12
23 NYCRR 500 (add-on)
Multi-Factor Authentication

MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review.

evidence an assessor asks for MFA architecture diagram; Coverage report by user population (employees, contractors, customers, privileged); VPN and SSO MFA configuration screenshots; Cloud application MFA enforcement evidence; CISO-approved compensating controls register with annual review; Service account inventory with interactive login disabled; Phishing-resistant MFA roadmap (Second Amendment alignment)

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 8.4.1
PCI DSS v4.0.1 (add-on)
MFA for non-console administrative CDE access

Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone.

evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts

PCI DSS 8.4.3
PCI DSS v4.0.1 (add-on)
MFA for remote access that could reach CDE

MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network.

evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-AC.7
Cyber Essentials
MFA for Administrative Accounts

Multi-factor authentication must be enabled for all administrative accounts on cloud services and where technically feasible on internal systems.

evidence an assessor asks for MFA enrolment per admin; Conditional Access policy targeting admin roles; PAM enforcement

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 8.4.1
PCI DSS v4.0.1 (add-on)
MFA for non-console administrative CDE access

Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone.

evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts

PCI DSS 8.4.3
PCI DSS v4.0.1 (add-on)
MFA for remote access that could reach CDE

MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network.

evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.5
ISO/IEC 27001:2022 (lens)

Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5.

evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 30 by the default rule (multi-factor authentication), unless it is marked not sure (day 90). The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule