PCI DSS 4.0
Req 8: Identify and Authenticate Users

PCI DSS 4.0 8.4.3: 8.4.3 MFA for remote access that could reach CDE

MFA must be implemented for all remote access that originates outside the entity's network and could access or affect the CDE. Applicability: covers all user accounts able to access the network remotely where that access leads, or could lead, into the CDE, including staff, both users and administrators, and third parties such as vendors, suppliers, service providers and customers. Remote access to a network segment properly isolated from the CDE does not need MFA, though MFA is recommended for every remote connection into the entity's networks. It covers every kind of system component (cloud and hosted systems, on-premises applications, workstations, servers, endpoints and network security devices) and both direct and web-based access. The guidance defines MFA as presenting at least two of the three factor types from 8.3.1. Customized approach objective: a single authentication factor is never enough to gain remote access into the entity's network.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 49 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • MA-4 Nonlocal Maintenance
  • PE-17 Alternate Work Site

FedRAMP Moderate · 6 controls

  • AC-17 Remote Access
  • AC-17(1) Monitoring and Control
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device (IA-2(6))
  • MA-4 Nonlocal Maintenance
  • PE-17 Alternate Work Site

CMMC 2.0 · 5 controls

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary

CIS Controls v8 · 3 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.4 Require MFA for Remote Network Access

NIST SP 800-53 Rev 5 · 3 controls

  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working

ISO 27001:2022 · 2 controls

  • 6.7 Remote working
  • 8.5 Secure authentication

ISO 27002:2022 · 2 controls

  • 6.7 Remote working
  • 8.5 Secure authentication

NIST SP 800-171 Rev 3 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-FW.3 Block Unauthenticated Inbound Connections
  • CE-SC.6 Multi-Factor Authentication for Cloud Services
  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • ASD37-20 Multi-factor authentication (Essential)
  • SEC02-BP04 Rely on a centralized identity provider
  • IM-7 Restrict resource access based on conditions

C5 (Germany) · 1 control

ISO 27701:2019 · 1 control

  • 6.3.2 Mobile devices and teleworking

NIS2 Directive · 1 control

  • Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications

NIST SP 800-172 · 1 control

  • 3.5.3e Prohibit Connection of Unknown or Unverified System Components
  • P2-4.3.1 P2-4.3.1 Multi-factor for remote access into the 3DE

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Req 8: Identify and Authenticate Users

You are reading one control. How much of PCI DSS 4.0 have you already done?

PCI DSS 4.0 8.4.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.