A solution platform can boast all day long about its amazing capabilities and revolutionary functionality, but what about real-life results?
Multi-Factor Authentication (MFA) is a core security requirement in NIST SP 800-171; however, it’s also one of the most frequently misinterpreted controls.
This guide breaks down what 3.5.3 means in plain language, and then walks through what implementation and evidence collection look like inside ASCERA step-by-step.
Control IA.L2-3.5.3 – Multifactor Authentication states that organizations must use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Put simply, the purpose of this control is to require users to authenticate using multiple factors (e.g. password + security token, biometric + PIN) before accessing systems. This reduces the risk of unauthorized access caused by password compromise, credential theft, or brute-force attacks.
Control 3.5.3 applies differently based on account type and access method. All privileged accounts must use multifactor authentication for both local access and network access. Non-privileged accounts must use multifactor authentication when accessing systems over a network.
NIST defines access types as either local access or network access. Local access is access obtained by direct connections without the use of networks. Network access is access obtained through network connections, including remote access through external networks.
Examples include:
Because most modern environments rely heavily on network-based systems, many access scenarios fall under network access. If there is uncertainty whether an access scenario is local or network-based, a conservative approach is to treat it as network access and enforce multifactor authentication.
When assessing this control, the following must be determinable:
Privileged accounts are identified (a)
Multifactor authentication is implemented for local access to privileged accounts (b)
Multifactor authentication is implemented for network access to privileged accounts (c)
Multifactor authentication is implemented for network access to non-privileged accounts (d)
Evidence must demonstrate that these conditions are met across applicable systems.
Multifactor authentication requires the use of at least two different factor types:
Some MFA solutions include hardware authenticators, smart cards, or authenticator applications. MFA may be applied at the system logon level or, when needed, at the application level to provide additional protection.
Organizations can satisfy this control if they:
These approaches reflect standard control implementation patterns described in the source material.
Assessors typically review:
Assessors may examine, interview, or test the following:
Identification and authentication policy; procedures addressing user identification and authentication; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; list of system accounts; other relevant documents or records.
Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators.
Mechanisms supporting or implementing authenticator management capability.
After implementing MFA, organizations must document enforcement to meet assessment demands. Below is how the control content above appears when viewed and supported inside ASCERA.
The overview page for control IA.L2-3.5.3 in ASCERA displays:
ASCERA provides a dedicated assessment objectives tab for users to track progress with each individual objective within the control:
ASCERA allows users to directly upload evidence for the control and automatically map evidence across any other relevant controls:
Every control in ASCERA contains in-depth written and video guidance:
CMMC control 3.5.3 Multifactor Authentication doesn’t have to be confusing. By following the above guidance, your organize can ensure a passing status.
ASCERA makes it easy for organizations to manage complex controls like 3.5.3. Want a free trial or a demo? Get in touch today and we’d love to share how ASCERA can help.
In the ever-evolving landscape of compliance, the responsibilities of security compliance professionals have grown exponentially. Amidst the complexity of compliance...