FedRAMP Controls / IA
IA-2(8) Access to Accounts — Replay Resistant
Family IA
Baselines moderate
Mapped KSIs 2
Control statement
Implement replay-resistant authentication mechanisms for access to {{ insert: param, ia-02.08_odp }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-IAM-01 | Phishing-Resistant MFA Enforce multi-factor authentication (MFA) using methods that are difficult to intercept or impersonate (phishing-resistant MFA) for all user authentication. | Identity and Access Management |
| KSI-IAM-02 | Passwordless Authentication Use secure passwordless methods for user authentication and authorization when feasible, otherwise enforce strong passwords with MFA. | Identity and Access Management |