unified

UC-ACCESS-09 — Authenticate all users with multi-factor authentication

Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-09
title
Authenticate all users with multi-factor authentication
statement
Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    IA-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    IA-8
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    PR.AA-03
    coverage
    partial
    delta
    service and hardware authentication satisfied by the device/service authentication control
    relationship
    intersects_with
  • framework
    nist-csf-2
    control_id
    PR.AA-04
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.5
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.12
    coverage
    partial
    delta
    amended 500.12 requires MFA for any access to any information system
    relationship
    intersects_with
  • framework
    pci-dss
    control_id
    PCI-Req8
    coverage
    partial
    delta
    account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls
    relationship
    intersects_with
  • framework
    hipaa
    control_id
    HIPAA-164.312(d)
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections