Essential Eight · Mitigation strategies
E8-3 Multi-factor authentication
Enforce multi-factor authentication for users, remote access and privileged actions.
Mapped across 16 provisions
Equivalent and related requirements in other frameworks and regulations.
- CIS Controls v8PartialCurated6.1 Establish an access granting process
Access control & identity
- Cyber EssentialsPartialCuratedCE-3 User access control
Access control & identity
- DORAPartialCuratedArt. 9 Protection and prevention
Access control & identity
- Essential EightPartialCuratedE8-4 Restrict administrative privileges
Access control & identity
- GLBAPartialCurated§314.4(c)(1) Access controls
Access control & identity
- HIPAAPartialCurated§164.312(a)(1) Access control
Access control & identity
- ISO 27001PartialCuratedA.5.15 Access control
Access control & identity
- ISO 27001PartialCuratedA.5.16 Identity management
Access control & identity
- NIS2PartialCuratedArt. 21(2)(i) Access control and asset management
Access control & identity
- NIST 800-171PartialCurated3.1.1 Limit system access to authorized users
Access control & identity
- NIST 800-53PartialCuratedAC-2 Account management
Access control & identity
- NIST CSF 2.0PartialCuratedPR.AA-01 Identities and credentials managed
Access control & identity
- NIST CSF 2.0PartialCuratedPR.AA-05 Access permissions and authorizations enforced
Access control & identity
- PCI DSSPartialCuratedReq. 7 Restrict access by business need to know
Access control & identity
- PCI DSSPartialCuratedReq. 8 Identify users and authenticate access
Access control & identity
- SOC 2PartialCuratedCC6.1 Logical access security controls
Access control & identity