Frameworks / BSI IT-Grundschutz / BSI-03 BSI IT-Grundschutz
BSI IT-Grundschutz: Access Control & Identity
BSI IT-Grundschutz BSI-03: Multi-factor authentication requirements Multi-factor authentication requirements. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
What else in your programme already covers this This control maps to 292 controls across 157 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
3.10 Encrypt Sensitive Data in Transit 3.7 Establish and Maintain a Data Classification Scheme 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) Part11.300 Controls for identification codes and passwords (21 CFR §11.300) Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) 6.4 Logging and Monitoring 6.5 Preparing and Distributing Audit Report 6.4 Logging and Monitoring 6.5 Preparing and Distributing Audit Report NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security APPI-A26 Report of Leakage to the Commission and Notification to the Person FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) 62351-8 Role-based access control (RBAC) 23837-1.7.3 Authentication and classical post-processing NIS2I-6 Access Control, Asset Management, and Physical Security NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information RCEPEC-1 Online Personal Information Protection (12.13) SOC2-CC6.3 Role-based access and least privilege are enforced SOC-CY-S1 Logical and Physical Access Controls SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures URUGUAY-3 Sensitive Data, Health Data, Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in BSI IT-Grundschutz: Access Control & Identity Query this from an agent The graph holds this control, the 292 it maps to, and the evidence behind each claim, over MCP and REST.