Security Questionnaire Mapper
Access and identity ยท question family

Multi-factor authentication: the clause the question tests

Whether a second factor is required, for whom and on which paths into the customer's data.

How the customer usually asks it

example

"Is multi-factor authentication enforced for all remote access?"

Read this question

Anchor clauses

8 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20228.5 Secure authentication
SOC 2 (Trust Services Criteria)CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
SIG (Shared Assessments)domain H Access Control
CSA Cloud Controls Matrix v4.0.1IAM-14 Strong Authentication
NIST Cybersecurity Framework 2.0PR.AA-03 Users, services, and hardware are authenticated
NIST SP 800-53 Rev 5IA-2 Identification and authentication of organizational users
PCI DSS v4.0.18.4.2 MFA is implemented for all non-console access into the CDE
HIPAA Security Rule (45 CFR 164)164.312(d) Person or Entity Authentication (Standard)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

Configuration evidence showing which systems require a second factor, which users it covers, and the exceptions with their reason.

The clauses, with what an assessor asks for

ISO 27001 8.5 Secure authentication

Implement authentication technologies and procedures based on access restrictions and policy.

Evidence an assessor expects: Authentication policy; Credential provisioning; MFA implementation; Access log monitoring; Privileged account controls
Where answers usually fall short: Reliance on static passwords only; Inconsistent MFA enforcement across systems
Source: ISO/IEC 27001:2022
SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: Inventory of information assets with classification and owner; Access control software configuration and the rule sets that enforce it; Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software; Network segmentation design with firewall or ACL rule review evidence; Register of points of access used by outside entities and the data that flows through each
Where answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
Source: SOC 2 (Trust Services Criteria)
SIG domain H Access Control

What it asks for, in one line (the standard's own text is not quoted here):

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Evidence an assessor expects: Access management policy; User access review reports; Privileged access management tool logs; Joiner mover leaver workflows
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
CSA CCM IAM-14 Strong Authentication

What it asks for, in one line (the standard's own text is not quoted here):

Authenticate access to systems, applications and data, using multifactor authentication at minimum for privileged users and sensitive data, and digital certificates or equivalent strength for system identities.

Evidence an assessor expects: Authentication configuration per system showing the factors required; Evidence multifactor authentication covers all privileged users and sensitive data access; The mechanism used for system identity authentication; Exception records where multifactor authentication is not applied
Where answers usually fall short: Multifactor authentication enforced at the perimeter but bypassable by direct application access; Service and system identities authenticating with static shared secrets
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF PR.AA-03 Users, services, and hardware are authenticated

Users, services, and hardware are authenticated.

Evidence an assessor expects: Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review
Where answers usually fall short: MFA fatigue not addressed; Legacy protocols still enabled
Source: NIST Cybersecurity Framework 2.0
SP 800-53 IA-2 Identification and authentication of organizational users

Requires organizational users to be uniquely identified and authenticated, and requires that unique identity to be carried through to the processes that act on their behalf, so that system activity is attributable to a specific person.

Evidence an assessor expects: Directory or identity store showing unique accounts per organizational user; Authentication configuration including multi-factor where required; Evidence that process and session activity carries the initiating user identity; Register of any shared accounts with justification and compensating attribution
Where answers usually fall short: Shared administrative accounts destroy attribution at exactly the highest privilege; Automation runs under a generic identity that hides who initiated the action
Source: NIST SP 800-53 Rev 5
PCI DSS 8.4.2 MFA is implemented for all non-console access into the CDE

What it asks for, in one line (the standard's own text is not quoted here):

MFA is implemented for all non-console access into the CDE

Evidence an assessor expects: Network and system configurations showing multi-factor authentication is implemented for all non-console access into the cardholder data environment; Observation of a non-administrative user logging in with evidence multi-factor was required; Complete enumeration of non-console access paths into the environment, including application, remote desktop and API paths; Evidence covering user accounts as well as administrative ones; Handling of accounts or paths that cannot support multi-factor, with the compensating position documented
Where answers usually fall short: Multi-factor required for administrators under 8.4.1 while ordinary user access into the environment still relies on a single factor; Application to application and batch access paths into the environment excluded with no documented position on why
Source: PCI DSS v4.0.1
HIPAA 164.312(d) Person or Entity Authentication (Standard)

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.

Evidence an assessor expects: Authentication standard aligned to NIST SP 800-63B; MFA deployment report; Service account authentication design; Federation and SSO design
Where answers usually fall short: No MFA on ePHI access; Weak factor combinations
Source: HIPAA Security Rule (45 CFR 164)

Other families in access and identity