Control detail

MFA enforcement for remote access

ctl-002 · PREVENTIVE · CONTINUOUS

ctl-002

All remote and privileged sessions require multi-factor authentication.

Key control
Type
PREVENTIVE
Automation
AUTOMATED
Frequency
CONTINUOUS
Owner
Information Security

Control Design Assessment (CDA)

Procedures evaluating whether the control is designed adequately.

  1. 1.Inspect the authentication policy configuration to confirm MFA is enforced for all remote and privileged sessions.PR.AA-02
  2. 2.Confirm the control cannot be bypassed by legacy or fallback authentication paths.

Control Operating Effectiveness (COE)

Procedures evaluating whether the control operated over the testing period.

  1. 1.Select 25 remote sessions across the period and confirm MFA was challenged and satisfied.
  2. 2.Attempt an authentication without a second factor using a test account and confirm access is denied.PR.AA-02
  3. 3.Review configuration change logs to confirm the MFA policy was not disabled during the period.DE.CM-09

Linked risks

  • Privileged access misusemitigation 2
  • Mobile channel account takeovermitigation 1
  • Identity federation outagemitigation 1

Framework mappings & latest test

IAM-14
Latest test:PASS2026-02-15