CCC.Core.C03: Implement Multi-factor Authentication (MFA) for Access
Control ID:CCC.Core.C03
Title:Implement Multi-factor Authentication (MFA) for Access
Objective:Ensure that all sensitive activities require two or more identity
factors during authentication to prevent unauthorized access.
Control Family:
Identity and Access Management
Related Threats
ID | Title | Description | External Mappings | Capability Mappings | Control Mappings |
---|---|---|---|---|---|
CCC.Core.TH01 | Access Control is Misconfigured | Misconfigured access controls may grant excessive privileges or fail to restrict unauthorized access to the service and its child resources. This could result in a loss of data confidentiality or tolerance of unauthorized actions which impact the integrity and availability of resources and data. | 1 | 1 | 0 |
Related Capabilities
ID | Title | Description |
---|---|---|
CCC.Core.F06 | Access Control | The service automatically enforces user configurations to restrict or allow access to a specific component or a child resource based on factors such as user identities, roles, groups, or attributes. |
Guideline Mappings
Reference ID | Entry ID | Strength | Remarks |
---|---|---|---|
NIST-CSF | PR.AC-7 | 0 | - |
CCM | IAM-03 | 0 | - |
CCM | IAM-08 | 0 | - |
ISO_27001 | 2013 A.9.4.2 | 0 | - |
NIST_800_53 | IA-2 | 0 | - |