Uniquely identify and authenticate organizational users and associate identity with processes acting on behalf of users.
What else in your programme already covers this
This control maps to 47 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
8.2.1 All users are assigned a unique ID before access to system components or cardholder data is allowed
8.2.4 Addition, deletion, and modification of user IDs, authentication factors, and other identifier objects are managed as follows: • Authorized with the appropriate approval. • Implemented with only the privileges specified on the documented approval
8.3.1 All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you
8.4.2 MFA is implemented for all non-console access into the CDE