Rule ID
SV-288136r1252911_rule
Version
V1R0.1
Without the use of MFA, the ease of access to privileged functions is greatly increased. MFA requires the use of two or more factors to achieve authentication. Factors include: (i) Something a user knows (e.g., password/PIN); (ii) Something a user has (e.g., cryptographic identification device, token); or (iii) Something a user is (e.g., biometric). The current DoW multifactor solution is the common access card (CAC). Other DoW or authorizing official (AO)-approved solutions may be implemented.
Review application documentation and configuration settings to determine if the application is using an approved MFA solution to authenticate organizational users. If an approved MFA solution is not being used, this is a finding.
Configure the application to use an approved MFA solution to uniquely identify and authenticate organizational users.