Skip to content

IA-2.1: Multi-factor Authentication to Privileged Accounts

An OSCAL Control

Statement

    • Implement multi-factor authentication for access to privileged accounts.

        • Requirement:

          According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).

        • Requirement:

          Multi-factor authentication must be phishing-resistant.

        • Guidance:

          Multi-factor authentication to subsequent components in the same user domain is not required.