Skip to content

IA-2.2: Multi-factor Authentication to Non-privileged Accounts

An OSCAL Control

Statement

    • Implement multi-factor authentication for access to non-privileged accounts.

        • Requirement:

          According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).

        • Requirement:

          Multi-factor authentication must be phishing-resistant.

        • Guidance:

          Multi-factor authentication to subsequent components in the same user domain is not required.