Controls / Multi-factor authentication
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: turn on multi-factor sign-in for remote access and every administrator account.
In Australia
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1173 Essential Eight, Maturity Level Two | Multi-factor authentication is used to authenticate privileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1173 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enforcing multi-factor authentication for privileged users of systems, including console and remote administration; Sample of privileged sign-in logs showing the second factor |
| ISM-0974 Essential Eight, Maturity Level Two | Multi-factor authentication is used to authenticate unprivileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-0974 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enforcing multi-factor authentication for unprivileged users signing in to systems (workstations and remote access); Coverage report of users enrolled |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 8.4.1 PCI DSS v4.0.1 (add-on) | MFA for non-console administrative CDE access Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone. evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts |
| PCI DSS 8.4.3 PCI DSS v4.0.1 (add-on) | MFA for remote access that could reach CDE MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network. evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 6.4 CIS Controls v8.1 | Require MFA for remote network access. evidence an assessor asks for Inventory of remote access paths, including VPN, ZTNA, RDP gateways and vendor support tools, each mapped to its MFA enforcement point; Access control standard requiring MFA on every remote network connection, including third parties, with the approver for any exception; VPN, ZTNA or remote desktop gateway configuration requiring a second factor for every remote session; Remote access logs showing MFA outcome per session, with any single-factor connections investigated |
| CIS 6.5 CIS Controls v8.1 | Require MFA for Administrative Access Where supported, require MFA on every account with administrative access, on every enterprise asset, whether the asset is managed on site or by a third-party provider. evidence an assessor asks for MFA configuration for all administrative accounts, on-site and third-party managed; Report of admin accounts with MFA enrolment status; Privileged access standard requiring MFA for all administrative logons, including provider-managed assets; PAM or identity provider policy export enforcing MFA on admin roles, cloud consoles and hypervisor management; Admin logon records sampled across on-site and hosted assets showing MFA used on each |
| PR.AA-03 NIST CSF 2.0 | Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review |
FTC Safeguards Rule, when it applies
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 314.4(c)(5) FTC Safeguards Rule (add-on) | 314.4(c)(5) Multi-factor authentication Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls. evidence an assessor asks for MFA enforcement on every information system access, including remote and administrative access; Qualified Individual's written approval of any equivalent control |
23 NYCRR 500, when it applies
Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 500.12 23 NYCRR 500 (add-on) | Multi-Factor Authentication MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review. evidence an assessor asks for MFA architecture diagram; Coverage report by user population (employees, contractors, customers, privileged); VPN and SSO MFA configuration screenshots; Cloud application MFA enforcement evidence; CISO-approved compensating controls register with annual review; Service account inventory with interactive login disabled; Phishing-resistant MFA roadmap (Second Amendment alignment) |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 8.4.1 PCI DSS v4.0.1 (add-on) | MFA for non-console administrative CDE access Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone. evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts |
| PCI DSS 8.4.3 PCI DSS v4.0.1 (add-on) | MFA for remote access that could reach CDE MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network. evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.7 Cyber Essentials | MFA for Administrative Accounts Multi-factor authentication must be enabled for all administrative accounts on cloud services and where technically feasible on internal systems. evidence an assessor asks for MFA enrolment per admin; Conditional Access policy targeting admin roles; PAM enforcement |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 8.4.1 PCI DSS v4.0.1 (add-on) | MFA for non-console administrative CDE access Personnel with administrative access who reach the CDE through any non-console connection must use MFA. The guidance defines that using the same factor twice, such as two passwords, does not count as MFA. Applicability: covers every person holding administrative or elevated privileges who reach the CDE over a non-console connection, meaning logical access across a network interface rather than a direct physical connection. Objective under the customized approach: nobody can obtain administrative access into the CDE using a single factor alone. evidence an assessor asks for MFA configuration for jump hosts, bastions, PAM and admin consoles into the CDE; List of administrative access paths into the CDE with the MFA control on each; Observation record of an administrator logging in with MFA; MFA enrolment report for all administrative accounts |
| PCI DSS 8.4.3 PCI DSS v4.0.1 (add-on) | MFA for remote access that could reach CDE MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network. evidence an assessor asks for VPN, VDI and remote access gateway MFA configuration; Inventory of remote access methods, including vendor tools, with MFA status; Segmentation evidence for any remote access path claimed to be isolated from the CDE; Observation records of employee and third-party remote connections |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.5 ISO/IEC 27001:2022 (lens) | Secure authentication technologies and procedures are to be put in place, driven by the information access restrictions and the access control policy. Purpose (stated in ISO/IEC 27002:2022): ensures users and entities are securely authenticated when granted access to systems, applications and services. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.5. evidence an assessor asks for Statement of Applicability entry for control A.8.5, showing inclusion or justified exclusion, implementation status and the risks it treats; An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules; Log-on configuration showing warning banners, generic error messages, lockout or throttling after failed attempts and masked password entry; Authentication logs recording successful and failed attempts, with alerting on suspected brute force |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 by the default rule (multi-factor authentication), unless it is marked not sure (day 90). The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.