FedRAMP Controls / IA

IA-2(6) Access to Accounts —separate Device

Family IA
Baselines moderate
Mapped KSIs 0

Control statement

Implement multi-factor authentication for {{ insert: param, ia-02.06_odp.01 }} access to {{ insert: param, ia-02.06_odp.02 }} such that:
    (a) One of the factors is provided by a device separate from the system gaining access; and
    (b) The device meets {{ insert: param, ia-02.06_odp.03 }}.
        Guidance: PIV=separate device. Please refer to NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials.
        Guidance: See SC-13 Guidance for more information on FIPS-validated or NSA-approved cryptography.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

No 20x Key Security Indicators map to this control in the current catalog version.