Under active development Content is continuously updated and improved

IAC-06Multi-Factor Authentication (MFA)

Weight: 9

>Control Description

Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive/regulated data.

>Cross-Framework Mappings

CIS Controls v8

SOC 2 TSC

OSFI B-13

India SEBI Guidelines

SOC 2 TSC (Detailed)

CIS Controls v8.1 (Detailed)

IMO Maritime Cyber Risk

NAIC Model Law 668

NIST SP 800-207 Zero Trust

Data Privacy Management Principles

CISA CPG

CISA SSDAF

DoD ZTA Reference Architecture

Executive Order 14028

GLBA (16 CFR 314)

Ask AI

Configure your API key to use AI features.