UK Telecommunications (Security) Act 2021
Network Security Duties

UK Telecommunications (Security) Act 2021 UK-TSA-NET-02: Access Control and Authentication

Implement strong authentication for network access. Privileged access management for network functions. Multi-factor authentication for remote access and critical operations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 204 controls across 68 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

ISO 13485 · 4 controls

ISO 27043 · 4 controls

ISO 27799 · 4 controls

ISO/SAE 21434 · 4 controls

API 1164 · 3 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

IEC 62443 · 3 controls

ISO 27019 · 3 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 1800-32 · 3 controls

South Korea ISMS-P · 3 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27010:2015 · 2 controls

ISO/IEC 27011:2024 · 2 controls

NIST SP 800-190 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.2 Prior to granting access, registration and authorization processes are established
  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • 62351-8 Role-based access control (RBAC)

ISO 19011 · 1 control

  • 6.5 Preparing and Distributing Audit Report

ISO 20000-1 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27400:2022 · 1 control

ITIL 4 · 1 control

  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • UGA-10 Sensitive Personal Data Prohibition

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Virginia CDPA · 1 control

WCAG 2.2 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Network Security Duties

Query this from an agent

The graph holds this control, the 204 it maps to, and the evidence behind each claim, over MCP and REST.