FedRAMP Controls / IA

IA-2(2) Multi-factor Authentication to Non-privileged Accounts

Family IA
Baselines moderate
Mapped KSIs 2

Control statement

Implement multi-factor authentication for access to non-privileged accounts.
        Requirement: According to SP 800-63-3, SP 800-63A (IAL), SP 800-63B (AAL), and SP 800-63C (FAL).
        Requirement: Multi-factor authentication must be phishing-resistant.
        Guidance: Multi-factor authentication to subsequent components in the same user domain is not required.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-01Phishing-Resistant MFA
Enforce multi-factor authentication (MFA) using methods that are difficult to intercept or impersonate (phishing-resistant MFA) for all user authentication.
Identity and Access Management
KSI-IAM-02Passwordless Authentication
Use secure passwordless methods for user authentication and authorization when feasible, otherwise enforce strong passwords with MFA.
Identity and Access Management