ACC-03Identity and Access

Strong authentication

Authentication is proportionate to risk, with multi-factor authentication on administrative and remote access.

Why it exists

Credential theft remains the most common entry point.

What usually proves it

Authentication configuration, MFA coverage report, exceptions.

Smaller organizations

MFA on everything that matters, with no shared logins.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC6.1
  • Fully addressedISO/IEC 27001 Annex A · A.8.5
  • Fully addressedNIST Cybersecurity Framework · PR.AA-03
  • Fully addressedPCI DSS · 8.4
  • Partially addressedHIPAA Security Rule · 164.312(d) — Person or entity authentication without specifying factors.
  • Partially addressedGDPR · Art. 32 — Through appropriate measures.
  • Deliberately absentEU AI Act — Not addressed.
  • Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.