NIS2 Directive
NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

NIS2 Directive Art.21.2.j: Multi-factor or continuous authentication, secured communications and secured emergency communications

This point pulls together the authentication and communications controls the Directive names explicitly. Multi-factor authentication, or continuous authentication solutions in its place, is expected where appropriate, and the interesting question is always coverage: remote access, administrative access, and access to the systems behind the essential service are where absence matters most. Secured voice, video and text communications within the entity is the second limb. The third, secured emergency communication systems, is the one most often absent, and it is the one that decides whether the entity can coordinate during an incident in which its normal collaboration and directory services are unavailable or untrusted. A crisis plan that runs on the corporate messaging platform does not satisfy this if that platform is what has been compromised.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 4 controls

CIS Controls v8 · 4 controls

  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-6.4 Require MFA for Remote Network Access
  • CIS-6.5 Require MFA for Administrative Access

CMMC 2.0 · 4 controls

FedRAMP High · 4 controls

  • CP-8 Telecommunications Services
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • SC-8(1) Cryptographic Protection

FedRAMP Moderate · 4 controls

  • CP-8 Telecommunications Services
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • SC-8(1) Cryptographic Protection

ISO 27001:2022 · 4 controls

  • 5.14 Information transfer
  • 5.29 Information security during disruption
  • 8.20 Networks security
  • 8.5 Secure authentication

ISO 27002:2022 · 4 controls

  • 5.14 Information transfer
  • 5.29 Information security during disruption
  • 8.20 Networks security
  • 8.5 Secure authentication
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

NIST SP 800-171 Rev 3 · 4 controls

  • 03.05.03 Multi-Factor Authentication
  • 03.13.08 Transmission Confidentiality and Integrity
  • 03.13.12 Collaborative Computing Devices and Applications
  • 03.13.15 Session Authenticity

NIST SP 800-53 Rev 5 · 4 controls

  • NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
  • NIST800-SC-15 SC-15 Collaborative Computing Devices and Applications
  • NIST800-SC-47 SC-47 Alternate Communications Paths
  • NIST800-SC-8 SC-8 Transmission Confidentiality and Integrity

PCI DSS 4.0 · 4 controls

  • 4.2.2 4.2.2 PAN secured when sent by end-user messaging
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass

DORA · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Cybersecurity Risk-Management Measures (Article 21)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.21.2.j is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.