Multi-factor authentication: the clause the question tests
Whether a second factor is required, for whom and on which paths into the customer's data.
How the customer usually asks it
example"Is multi-factor authentication enforced for all remote access?"
Anchor clauses
8 frameworks| Framework | Anchor clause |
|---|---|
| ISO/IEC 27001:2022 | 8.5 Secure authentication |
| SOC 2 (Trust Services Criteria) | CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets |
| SIG (Shared Assessments) | domain H Access Control |
| CSA Cloud Controls Matrix v4.0.1 | IAM-14 Strong Authentication |
| NIST Cybersecurity Framework 2.0 | PR.AA-03 Users, services, and hardware are authenticated |
| NIST SP 800-53 Rev 5 | IA-2 Identification and authentication of organizational users |
| PCI DSS v4.0.1 | 8.4.2 MFA is implemented for all non-console access into the CDE |
| HIPAA Security Rule (45 CFR 164) | 164.312(d) Person or Entity Authentication (Standard) |
Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.
Evidence expected
Configuration evidence showing which systems require a second factor, which users it covers, and the exceptions with their reason.
The clauses, with what an assessor asks for
ISO 27001 8.5 Secure authenticationImplement authentication technologies and procedures based on access restrictions and policy.
Where answers usually fall short: Reliance on static passwords only; Inconsistent MFA enforcement across systems
Source: ISO/IEC 27001:2022
SOC 2 CC6.1 Implements logical access security software, infrastructure and architectures over protected information assetsNamed, not quoted: the criteria text is not held in full here.
Where answers usually fall short: Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4; Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
Source: SOC 2 (Trust Services Criteria)
SIG domain H Access ControlWhat it asks for, in one line (the standard's own text is not quoted here):
Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
CSA CCM IAM-14 Strong AuthenticationWhat it asks for, in one line (the standard's own text is not quoted here):
Authenticate access to systems, applications and data, using multifactor authentication at minimum for privileged users and sensitive data, and digital certificates or equivalent strength for system identities.
Where answers usually fall short: Multifactor authentication enforced at the perimeter but bypassable by direct application access; Service and system identities authenticating with static shared secrets
Source: CSA Cloud Controls Matrix v4.0.1
NIST CSF PR.AA-03 Users, services, and hardware are authenticatedUsers, services, and hardware are authenticated.
Where answers usually fall short: MFA fatigue not addressed; Legacy protocols still enabled
Source: NIST Cybersecurity Framework 2.0
SP 800-53 IA-2 Identification and authentication of organizational usersRequires organizational users to be uniquely identified and authenticated, and requires that unique identity to be carried through to the processes that act on their behalf, so that system activity is attributable to a specific person.
Where answers usually fall short: Shared administrative accounts destroy attribution at exactly the highest privilege; Automation runs under a generic identity that hides who initiated the action
Source: NIST SP 800-53 Rev 5
PCI DSS 8.4.2 MFA is implemented for all non-console access into the CDEWhat it asks for, in one line (the standard's own text is not quoted here):
MFA is implemented for all non-console access into the CDE
Where answers usually fall short: Multi-factor required for administrators under 8.4.1 while ordinary user access into the environment still relies on a single factor; Application to application and batch access paths into the environment excluded with no documented position on why
Source: PCI DSS v4.0.1
HIPAA 164.312(d) Person or Entity Authentication (Standard)Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.
Where answers usually fall short: No MFA on ePHI access; Weak factor combinations
Source: HIPAA Security Rule (45 CFR 164)