Skip to main content

CCC.Core.CN03: Implement Multi-factor Authentication (MFA) for Access

Control ID:CCC.Core.CN03
Title:Implement Multi-factor Authentication (MFA) for Access
Objective:Ensure that all sensitive activities require two or more identity factors during authentication to prevent unauthorized access.
Control Family:
Identity and Access Management

Guideline Mappings

Reference IDEntry IDStrengthRemarks
CCM
IAM-14
3
Strong Authentication (Define, implement and evaluate processes - including MFA)

Assessment Requirements

IDDescriptionApplicability
CCC.Core.CN03.AR01When an entity attempts to modify the service through a user interface, the authentication process MUST require multiple identifying factors for authentication.
tlp-clear
tlp-green
tlp-amber
tlp-red
CCC.Core.CN03.AR02When an entity attempts to modify the service through an API endpoint, the authentication process MUST require a credential such as an API key or token AND originate from within the trust perimeter.
tlp-clear
tlp-green
tlp-amber
tlp-red
CCC.Core.CN03.AR03When an entity attempts to view information on the service through a user interface, the authentication process MUST require multiple identifying factors from the user.
tlp-amber
tlp-red
CCC.Core.CN03.AR04When an entity attempts to view information on the service through an API endpoint, the authentication process MUST require a credential such as an API key or token AND originate from within the trust perimeter.
tlp-amber
tlp-red