unified
UC-ACCESS-09 — Authenticate all users with multi-factor authentication
Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-09
- title
- Authenticate all users with multi-factor authentication
- statement
- Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- IA-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-8
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.AA-03
- coverage
- partial
- delta
- service and hardware authentication satisfied by the device/service authentication control
- relationship
- intersects_with
- framework
- nist-csf-2
- control_id
- PR.AA-04
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.5
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.12
- coverage
- partial
- delta
- amended 500.12 requires MFA for any access to any information system
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req8
- coverage
- partial
- delta
- account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls
- relationship
- intersects_with
- framework
- hipaa
- control_id
- HIPAA-164.312(d)
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to PR.AA-03 — Identity Management, Authentication, and Access Control: Users, services, and hardware are authenticated
- framework
- nist-csf-2
- control_id
- PR.AA-03
- coverage
- partial
- delta
- service and hardware authentication satisfied by the device/service authentication control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Employee Onboarding operates UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- Authentication Platform & Session Policy Operations operates UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to A.8.5 — Secure authentication
- framework
- iso-27001
- control_id
- A.8.5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- Identity Assurance Review oversees UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates Remote-work, mobile and split-tunneling exposure
- strength
- related
- rationale
- Enforced MFA for remote access reduces credential compromise from insecure off-premises environments.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to PCI-Req8 — Identify users and authenticate access to system components
- framework
- pci-dss
- control_id
- PCI-Req8
- coverage
- partial
- delta
- account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates Weak authentication and password management
- strength
- primary
- rationale
- MFA with credential validation only over protected channels directly remediates absent MFA and clear-text authentication.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to HIPAA-164.312(d) — Person or entity authentication before ePHI access
- framework
- hipaa
- control_id
- HIPAA-164.312(d)
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to IA-8 — Identification and Authentication (Non-organizational Users)
- framework
- nist-800-53
- control_id
- IA-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to IA-2 — Identification and Authentication (Organizational Users)
- framework
- nist-800-53
- control_id
- IA-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to 500.12 — Multi-factor authentication
- framework
- nydfs-500
- control_id
- 500.12
- coverage
- partial
- delta
- amended 500.12 requires MFA for any access to any information system
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates Phishing, spear-phishing and social engineering
- strength
- primary
- rationale
- MFA blocks account takeover even when a password is phished, the canonical defense against credential-harvesting social engineering.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication maps_to PR.AA-04 — Identity Management, Authentication, and Access Control: Identity assertions are protected, conveyed, and verified
- framework
- nist-csf-2
- control_id
- PR.AA-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-09 — Authenticate all users with multi-factor authentication mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- primary
- rationale
- MFA directly defeats account takeover using stolen credentials.
- System ITGC Operation operates UC-ACCESS-09 — Authenticate all users with multi-factor authentication