Skip to content

IA-2.6: Access to Accounts —separate Device

An OSCAL Control

Statement

    • Implement multi-factor authentication for access to such that:

      • (a)

        One of the factors is provided by a device separate from the system gaining access; and

      • (b)

        The device meets .

        • Guidance:

          PIV=separate device. Please refer to NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials.

        • Guidance:

          See SC-13 Guidance for more information on FIPS-validated or NSA-approved cryptography.