Phishing-Resistant MFA for Admin Accounts, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to prioritize adoption of phishing-resistant multi-factor authentication (MFA) for administrative accounts, across all of its product and service offerings.

Assessment Step

1
Phishing-Resistant MFA for Admin Accounts (Phishing-ResistantMFAforAdminAccounts)
Across all of its product and service offerings, does the organization prioritize adoption of phishing-resistant multi-factor authentication (MFA) for administrative accounts?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Phishing-Resistant MFA for Admin Accounts
Across all of its product and service offerings, the organization must prioritize adoption of phishing-resistant multi-factor authentication (MFA) for administrative accounts.
Citation
SBDP
(doc)