What counts as MFA on a cyber application
Multi-factor authentication is the control a cyber underwriter asks about most often. This page lists every MFA question in the held carrier documents, the ISO 27001:2022, SOC 2 and NIST CSF 2.0 controls each question reaches, and the evidence to have on file. It is drawn only from the held applications and the held control text; it never says what a carrier will accept.
What the held questions ask MFA over
- remote and administrative sign-in
- privileged and domain-admin access
- web-based email accessed outside the corporate network
- wireless networks, where a form asks for authentication at least as strong as WPA2
Our reading of the held questions: an answer holds up where the second factor is required for the scope the form names and cannot be switched off by the user. Where a form offers a partial option, the carrier reads that as a partial control, so answer it as it is.
The held MFA questions, mapped
Do you require Multi-Factor Authentication (MFA) for remote access to your network (both cloud-hosted and on- premises, including via Virtual Private Networks (VPNs)?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Do you require MFA for access to web-based email?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.15 Access control. Evidence to have on file: The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Multi-factor authentication in place for remote access by employees?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Multi-factor authentication in place for remote access by third parties?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
If Yes, are the cloud back-ups secured via two-factor authentication or other similar means?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.13 Information backup. Evidence to have on file: The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 A1.2 Environmental protection, backup and recovery infrastructure. Evidence to have on file: Backup policy defining scope, frequency and retention; Backup job monitoring and failure remediation records.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.DS-11 Backups of data are created, protected, maintained, and tested. Evidence to have on file: Backup policy with frequency and retention; Backup integrity test reports.
Is multi factor authentication (MFA) to access Email required?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Is multi factor authentication (MFA) for personal devices required?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.1 User end point devices. Evidence to have on file: The topic-specific endpoint policy covering classification limits, registration, software restrictions, updates, network connection rules, encryption, malware protection, remote wipe, backup and port control; Device management (MDM or endpoint management) reports showing enrolment, encryption, patch level, firewall and anti-malware status.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.7 Restricting and protecting information in transmission, movement and removal. Evidence to have on file: TLS and encryption standards for data in transit; Removable media policy and technical enforcement.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk. Evidence to have on file: Physical access control system inventory; Badge issuance and revocation records.
Is multifactor authentication (MFA) required to remotely connect to the network, all critical internet facing systems and privilege accounts?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.2 Privileged access rights. Evidence to have on file: An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
If "Yes": (1) Do you use 2-factor authentication to secure all remote access to your network?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
If "No", is RDP and/or RDG protected by two-factor authentication?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Do you use 2-factor authentication to secure all domain or network administrator accounts?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.2 Privileged access rights. Evidence to have on file: An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
Do you use 2-factor authentication to secure remote access to your email accounts?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
(b) segregated with 2-factor authentication access control?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.15 Access control. Evidence to have on file: The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.2 Registering and authorising users before issuing credentials. Evidence to have on file: Access request tickets with owner approval for a sample of new users, service accounts and API credentials; Termination records reconciled to account disablement dates.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization. Evidence to have on file: Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs.
Is Multi Factor Authentication used for access?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
If remote access is available, does the Applicant implement MFA for all remote access?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Does the Applicant or its Managed Security Service Provider, if applicable, implement MFA for all administrator access?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.2 Privileged access rights. Evidence to have on file: An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
Which of the of the following apply to your Multi-Factor Authentication (MFA) implementation?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Do you enforce Multi-Factor Authentication (MFA) for all employees, contractors, and partners on the following?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Is multifactor authentication (MFA) required for all internal, external, and vendor access to the applicant's network?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.19 Information security in supplier relationships. Evidence to have on file: The topic-specific supplier relationship policy and its communication record; A supplier inventory categorized by type and by the information, services and infrastructure each can access.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC9.2 Assessing and managing vendor and business partner risk. Evidence to have on file: Vendor inventory with risk tiers and the review frequency set for each tier; Due diligence records, for example vendor SOC reports reviewed with complementary controls noted.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders. Evidence to have on file: Third party risk management program charter; Supplier risk policy with tiering criteria.
If yes, does the applicant require strong authentication (e.g., two factor/ MFA?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Can backups only be accessed via an authentication mechanism (i.e., MFA/password vault/separate credentials or credential checkout?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.13 Information backup. Evidence to have on file: The topic-specific backup policy and backup plans stating scope, extent, frequency and retention per system aligned with RPO; Backup job monitoring reports with evidence that failed jobs were investigated and rerun.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 A1.2 Environmental protection, backup and recovery infrastructure. Evidence to have on file: Backup policy defining scope, frequency and retention; Backup job monitoring and failure remediation records.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization. Evidence to have on file: Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs.
Security & Controls MFA Is Multi-Factor Authentication (MFA) required for ALL remote access to your business' network?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Is MFA required for access to email?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Information Security and Cyber Infrastructure Self-Assessment 14 On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.24 Use of cryptography. Evidence to have on file: The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification; Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization. Evidence to have on file: Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs.
if you do not use wireless networks.) 15 Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
On your wireless networks; do you use security at least as strong as WPA2 authentication and encryption, and do you require two factor authentication (access token and password/account logon) before allowing wireless connections to your network?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.24 Use of cryptography. Evidence to have on file: The topic-specific cryptography policy with approved algorithms, key lengths, protocols and usage by information classification; Evidence of encryption on endpoints, removable media and data in transit, aligned with the policy.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization. Evidence to have on file: Identity management platform configuration baseline; Joiner mover leaver workflow with timing SLAs.
Do you require multi-factor authorization when your network is accessed remotely and/or when cloud resources are utilized?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
If "Yes", do you enforce Multi-Factor Authentication (MFA?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
If "Yes", do you use MFA to secure all remote access to your network, including any remote desktop protocol (RDP) connections?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Encore Fiduciary Cyber Liability Application (2.2022) Page 2 of 10 If MFA is used, complete the following: (1) Provide the name of your MFA provider: (2) Describe your MFA type: (3) Does your MFA configuration ensure that the compromise of a single device will only compromise a single authenticator?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.9 Configuration management. Evidence to have on file: Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates; Configuration records or a CMDB showing owner, last change date, template version and relationships between assets.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC8.1 Managing changes to procedures, software, data and infrastructure. Evidence to have on file: Change management policy covering normal, standard and emergency changes; Sample of change tickets with approval, testing evidence and deployer different from author.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.PS-01 Configuration management practices are established and applied. Evidence to have on file: Configuration management standards by platform; Hardening baselines and compliance reports.
Do you use MFA to protect all local and remote access to privileged user accounts?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.2 Privileged access rights. Evidence to have on file: An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
If "Yes", complete the following: (1) Provide the name of your PAM software provider: (2) Is access protected by MFA?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.8.2 Privileged access rights. Evidence to have on file: An inventory of privileged accounts per system (operating systems, databases, applications, cloud consoles) mapped to named individuals; Authorization records for each privileged grant with approver, justification and expiry.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
Does the Applicant use multi-factor authentication for access to critical applications or databases (including those that contain personally identifiable information, private health information or payment card information?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.34 Privacy and protection of personal identifiable information (PII). Evidence to have on file: The topic-specific privacy and PII protection policy and its communication to relevant parties; Privacy procedures communicated to everyone who processes PII.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 P1.1 Privacy notice to data subjects. Evidence to have on file: Published privacy notice with effective date and version history; Evidence notice is presented at collection points (forms, apps).
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed. Evidence to have on file: Legal and regulatory obligations register with owners; Contractual security clauses summary across customer base.
Is multi-factor authentication (MFA) in place for web-based email logins?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.15 Access control. Evidence to have on file: The topic-specific access control policy, approved and communicated, reflecting owner-defined business and security requirements; Access control rules or role models mapping entities (users, services, devices) to rights, consistent with classification.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Do all users with remote access provide at least two different forms of identification ('multi-factor authentication') to verify their identity prior to log-in?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.6.7 Remote working. Evidence to have on file: The topic-specific remote working policy defining conditions, permitted work, information classifications allowed and systems accessible; Remote access configuration showing multi-factor authentication, secure channels or virtual desktops.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.6 Protection against threats from outside the system boundary. Evidence to have on file: Firewall and security group rule sets with review evidence; MFA enforced on VPN, remote and administrative access.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorized logical access and usage. Evidence to have on file: Network segmentation design with zones and trust levels; Firewall and access control list governance.
Do you require multi-factor authentication for all online banking logins?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
Do you ensure multi-factor authentication for any fund transfer?
- ISO 27001:2022 A.8.5 Secure authentication. Evidence to have on file: An authentication standard linking required authentication strength to information classification and system criticality; MFA configuration and coverage reports for critical systems, remote access and privileged access, including conditional or risk-based rules.
- ISO 27001:2022 A.5.17 Authentication information. Evidence to have on file: Credential issuance procedure requiring identity verification before new, replacement or temporary credentials are provided; Evidence that initial credentials are unique, delivered over protected channels and changed at first use.
- ISO 27001:2022 A.5.3 Segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- SOC 2 CC6.1 Logical access security over protected information assets. Evidence to have on file: Asset inventory with classification for in-scope systems; Identity provider configuration showing MFA and password policy.
- SOC 2 CC6.3 Role-based access, least privilege and segregation of duties. Evidence to have on file: the bank or treasury platform dual-authorisation setup and the payment approval workflow, showing a second approver on a different device above the threshold; the callback or out-of-band verification procedure for a change to payee bank details, with a dated example.
- NIST CSF 2.0 PR.AA-03 Users, services, and hardware are authenticated. Evidence to have on file: Multi factor authentication coverage report; Phishing resistant authentication rollout plan.
- NIST CSF 2.0 PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties. Evidence to have on file: Access policy framework with role definitions; Privileged access management deployment evidence.
Map your own answers in the tool. The other worked answer is the funds-transfer verification question.