Belgium CyberFundamentals
Belgium CyberFundamentals: Protect

Belgium CyberFundamentals BE-CF-03: Multi-factor authentication requirements

Multi-factor authentication requirements. Implements CyFun PR.AC-7: users, devices and other assets are authenticated commensurate with the risk of the transaction, including multi-factor authentication.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 19 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AMLCTF-35 Identity Verification Standard

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Belgium CyberFundamentals: Protect

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.