Skip to content

Multi-Factor Authentication

What is Multi-Factor Authentication?

An authentication method requiring users to present two or more distinct types of evidence to verify their identity before gaining access.

Information Security

Each of these is named in at least one of the same controls as multi-factor authentication. The number is how many controls name both.

What the standards actually require on multi-factor authentication

Requirements naming multi-factor authentication across 6 standards, quoted from the control text.

Multi-factor authentication is used to authenticate unprivileged users of systems.

ISM-0974 · Multi-factor authentication is used to authenticate unprivileged users of systems.

MFA on privileged users and important data repositories; phishing-resistant where possible.

E8-MFA-ML2 · Multi-Factor Authentication - Maturity Level 2

Require multi factor authentication at LoA 3 and 4 combining factors from different categories (knowledge, possession, inherence).

ISO29115-7.2 · Multi Factor Authentication
NIST SP 800-1713 controls

Use multi-factor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

171-IA-2 · Multi-Factor Authentication

MFA must be applied to all administrative accounts on cloud services and to all user accounts on cloud services where supported by the provider.

CE-SC.6 · Multi-Factor Authentication for Cloud Services

Determines whether multi-factor authentication is implemented for the required access, including privileged and network access, and whether it cannot be bypassed.

171A-03.05.03 · Multi-Factor Authentication

Questions people ask about multi-factor authentication

What is Multi-Factor Authentication?
An authentication method requiring users to present two or more distinct types of evidence to verify their identity before gaining access.
Why is Multi-Factor Authentication important for compliance?
Multi-Factor Authentication is a key concept in Information Security. Understanding multi-factor authentication helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Multi-Factor Authentication?
Multi-Factor Authentication appears in the requirement text of Australian Information Security Manual, ACSC Essential Eight, ISO/IEC 29115:2023 - Entity Authentication Assurance Framework, NIST SP 800-171, UK Cyber Essentials. Across these standards we have identified 35 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Multi-Factor Authentication?
Explore our compliance framework pages to see how multi-factor authentication applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Multi-Factor Authentication applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.