Two-Factor Authentication
What is Two-Factor Authentication?
An authentication method that requires two different types of verification, such as a password and a one-time code, before granting access.
Frameworks that govern two-factor authentication
What the standards actually require on two-factor authentication
Requirements naming two-factor authentication across 3 standards, quoted from the control text.
Control entry at every access point using an access control system whose documented rules grant least privilege authorisations, revoke unused rights after two and six months, enforce two factor authentication for areas holding customer data, escort visitors an...
C5-PS-04 · Physical site access control →Remove obscure access vectors and back doors, especially modems; limit any remaining access. Where possible implement monitoring-only access enforced by data diodes (not software-enforced read-only); prohibit persistent vendor connections;
CISA-ICS-7S-6 · Implement Secure Remote Access →Implement Online Financial Services Authentication + Payment Card Security per MAS TRM Chapters 12 + 13. Chapter 12 Online Financial Services Authentication - Two-Factor Authentication (2FA) for customer-facing online services + Strong Customer Authentication...
MAS-TRM-Online-Authentication-Payment-Card-Chapters-12-13-2FA-Strong-Customer-Authentication-PCI-DSS · MAS TRM Online Authentication + Payment Card + Chapters 12-13 + 2FA + Strong Customer Authentication + PCI DSS →Questions people ask about two-factor authentication
What is Two-Factor Authentication?
Why is Two-Factor Authentication important for compliance?
Which compliance frameworks address Two-Factor Authentication?
Where can I learn more about Two-Factor Authentication?
See how Two-Factor Authentication applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.