ACC-03Identity and Access
Strong authentication
Authentication is proportionate to risk, with multi-factor authentication on administrative and remote access.
Why it exists
Credential theft remains the most common entry point.
What usually proves it
Authentication configuration, MFA coverage report, exceptions.
Smaller organizations
MFA on everything that matters, with no shared logins.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.1
- Fully addressedISO/IEC 27001 Annex A · A.8.5
- Fully addressedNIST Cybersecurity Framework · PR.AA-03
- Fully addressedPCI DSS · 8.4
- Partially addressedHIPAA Security Rule · 164.312(d) — Person or entity authentication without specifying factors.
- Partially addressedGDPR · Art. 32 — Through appropriate measures.
- Deliberately absentEU AI Act — Not addressed.
- Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.