Skip to main content

💼 IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H)

Description

Implement multi-factor authentication for access to privileged accounts.

IA-2 (1) Additional FedRAMP Requirements and Guidance:

Guidance: Multi-factor authentication to subsequent components in the same user domain is not required.

Requirement: According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).

Requirement: Multi-factor authentication must be phishing-resistant.

Similar

  • Sections
    • /frameworks/nist-sp-800-53-r5/ia/02/01
  • Internal
    • ID: dec-c-b969b124

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST SP 800-53 Revision 5 → 💼 IA-2(1) Identification and Authentication (organizational Users) _ Multi-factor Authentication to Privileged Accounts2

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP Low Security Controls → 💼 IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H)2
💼 FedRAMP Moderate Security Controls → 💼 IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H)2

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (2)

PolicyLogic CountFlags
📝 AWS Account Root User Hardware MFA is not enabled. 🟢🟢 x3
📝 AWS IAM User MFA is not enabled for all users with console password 🟢1🟢 x6