PCI DSS 4.0 8.5.1: 8.5.1 MFA system resistant to replay and bypass
MFA systems must be implemented so that: the MFA system resists replay attacks; no user, including administrative users, can bypass MFA unless this is specifically documented and authorized by management by exception for a limited time; at least two distinct factor types are required; and all factors must succeed before access is granted. The guidance gives examples of replay protections, including unique session identifiers and keys, timestamps, time-based one-time passcodes and mechanisms that detect and reject duplicate authentication attempts. Objective under the customized approach: MFA systems resist attack and tightly control any administrative override. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
This control maps to 40 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of PCI DSS 4.0 have you already done?
PCI DSS 4.0 8.5.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of PCI DSS 4.0 your existing evidence covers. Hold ISO 27001:2022 and 139 of 280 PCI DSS 4.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 415 were rejected on the ISO 27001:2022 pair alone.