Secure by Design: A Guide for Manufacturers (CISA)
Secure by default tactics: product configuration practices – Secure by Design: A Guide for Manufacturers (CISA)

Secure by Design: A Guide for Manufacturers (CISA) DF-2: Mandate MFA for privileged users

Because administrators are high-value targets and often lack MFA, make MFA opt-out rather than opt-in and keep prompting administrators to enrol until they do; NCSC-NL's Mature Authentication Factsheet parallels CISA's guidance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Secure by default tactics: product configuration practices – Secure by Design: A Guide for Manufacturers (CISA)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.