Multifactor authentication is required for all access, where feasible
Multifactor authentication may not be supported by all assets within the function. Where feasible, stronger authentication controls, such as multifactor authentication reduce the risk of account misuse resulting from compromised credentials. Where multifactor authentication is not feasible, organizations may consider implementing mitigating controls depending on their risk appetite, threat environment, and operational needs.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-1b, ACCESS-1d, ACCESS-1g, ACCESS-1h, ACCESS-1i.