Under active development Content is continuously updated and improved

8.3.9If passwords/passphrases are used as the only authentication factor for user access (i.

>Requirement Description

If passwords/passphrases are used as the only authentication factor for user access (i.e., in any single-factor authentication implementation) then either: Passwords/passphrases are changed at least once every 90 days, OR The security posture of accounts is dynamically analyzed, and real-time access to resources is automatically determined accordingly. Applicability Notes This requirement does not apply to in-scope system components where MFA is used. This requirement is not intended to apply to user accounts on point-of-sale terminals that have access to only one card number at a time to facilitate a single transaction. This requirement does not apply to service providers’ customer accounts but does apply to accounts for service provider personnel.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.