Under active development Content is continuously updated and improved

8.4.3MFA is implemented for all remote network access originating from outside the entity’s network that could access or impact the CDE.

>Requirement Description

MFA is implemented for all remote network access originating from outside the entity’s network that could access or impact the CDE. Applicability Notes The requirement for MFA for remote access originating from outside the entity’s network applies to all user accounts that can access the network remotely, where that remote access leads to or could lead to access into the CDE. This includes all remote access by personnel (users and administrators), and third parties (including, but not limited to, vendors, suppliers, service providers, and customers). If remote access is to a part of the entity’s network that is properly segmented from the CDE, such that remote users cannot access or impact the CDE, MFA for remote access to that part of the network is not required. However, MFA is required for any remote access to networks with access to the CDE and is recommended for all remote access to the entity’s networks. The MFA requirements apply for all types of system components, including cloud, hosted systems, and on-premises applications, network security devices, workstations, servers, and endpoints, and includes access directly to an entity’s networks or systems as well as web-based access to an application or function.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.