MFA by Default, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to enable multi-factor authentication (MFA) by default for all users and administrators upon first registration, across all of its product and service offerings.

Assessment Step

1
MFA by Default (MFAbyDefault)
Across all of its product and service offerings, does the organization enable multi-factor authentication (MFA) by default for all users and administrators upon first registration?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

MFA by Default
Across all of its product and service offerings, the organization must enable multi-factor authentication (MFA) by default for all users and administrators upon first registration.
Citation
SBDP
(doc)