FedRAMP Controls / IA
IA-2(1) Multi-factor Authentication to Privileged Accounts
Family IA
Baselines moderate
Mapped KSIs 2
Control statement
Implement multi-factor authentication for access to privileged accounts.
Requirement: According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).
Requirement: Multi-factor authentication must be phishing-resistant.
Guidance: Multi-factor authentication to subsequent components in the same user domain is not required. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-IAM-01 | Phishing-Resistant MFA Enforce multi-factor authentication (MFA) using methods that are difficult to intercept or impersonate (phishing-resistant MFA) for all user authentication. | Identity and Access Management |
| KSI-IAM-02 | Passwordless Authentication Use secure passwordless methods for user authentication and authorization when feasible, otherwise enforce strong passwords with MFA. | Identity and Access Management |