ctl-002
All remote and privileged sessions require multi-factor authentication.
- Type
- PREVENTIVE
- Automation
- AUTOMATED
- Frequency
- CONTINUOUS
- Owner
- Information Security
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Inspect the authentication policy configuration to confirm MFA is enforced for all remote and privileged sessions.PR.AA-02
- 2.Confirm the control cannot be bypassed by legacy or fallback authentication paths.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 remote sessions across the period and confirm MFA was challenged and satisfied.
- 2.Attempt an authentication without a second factor using a test account and confirm access is denied.PR.AA-02
- 3.Review configuration change logs to confirm the MFA policy was not disabled during the period.DE.CM-09
Linked risks
- Privileged access misusemitigation 2
- Mobile channel account takeovermitigation 1
- Identity federation outagemitigation 1
Framework mappings & latest test
IAM-14
Latest test:PASS2026-02-15