Multi-Factor Authentication (MFA)
What is Multi-Factor Authentication (MFA)?
An authentication method that requires users to provide two or more verification factors to gain access to a resource. MFA combines something you know (password), something you have (token), and something you are (biometric).
Terms that appear alongside multi-factor authentication (mfa)
Each of these is named in at least one of the same controls as multi-factor authentication (mfa). The number is how many controls name both.
- multi factor authentication 12 shared controls
- authentication 12 shared controls
- nist 9 shared controls
- access control 8 shared controls
- role based access control 7 shared controls
- privileged access management pam 7 shared controls
- privileged access management 7 shared controls
- access management 7 shared controls
Frameworks that govern multi-factor authentication (mfa)
What the standards actually require on multi-factor authentication (mfa)
Requirements naming multi-factor authentication (mfa) across 6 standards, quoted from the control text.
Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →16 CFR 314.4(c)(1-9) the 9 SPECIFIC SAFEGUARD ELEMENTS (added by 2021 amendments). (1) ACCESS CONTROLS - place access controls + limit access to authorized users + role-based + least-privilege + periodic review + revoke access promptly upon termination/role ch...
FTC-Safeguards-9-Elements · 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) →HITECH 2024-2025 regulatory pipeline + sectoral application. KEY 2024-2025 INITIATIVES: (a) HIPAA SECURITY RULE NPRM (Notice of Proposed Rulemaking) issued by HHS OCR 27 December 2024 (89 FR 105672) proposing the FIRST MAJOR HIPAA Security Rule modernisation s...
HITECH-2024-2025-NPRM-ReproductiveHealth-Sectoral · HITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application →HL7 FHIR Authentication. SMART APP LAUNCH IMPLEMENTATION GUIDE v2.2.0 - foundational FHIR-based OAuth 2.0 / OAuth 2.1 + OpenID Connect framework + standardised app authorization.
HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend · HL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime →UR E26 Goal 2 (Protect) requires access control + authentication + authorization mechanisms for all CBS. Unique user identification (no shared accounts where feasible); strong password policy (per NIST SP 800-63B + IEC 62443 + ship operational reality);
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles · IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Questions people ask about multi-factor authentication (mfa)
What is Multi-Factor Authentication (MFA)?
Why is Multi-Factor Authentication (MFA) important for compliance?
Which compliance frameworks address Multi-Factor Authentication (MFA)?
Where can I learn more about Multi-Factor Authentication (MFA)?
See how Multi-Factor Authentication (MFA) applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.