Implement multi-factor authentication for access to non-privileged accounts.
Implement multi-factor authentication for access to non-privileged accounts.
[Withdrawn: Incorporated into IA-2(6).]
[Withdrawn: Incorporated into IA-2(1).]
When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources.
Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that: (a) One of the factors is provided by a device separate from the system gaining access; and (b) The device meets [Assignment: organization-defined strength of mechanism requirements].
[Withdrawn: Incorporated into IA-2(2).]
Implement replay-resistant authentication mechanisms for access to [Selection (one or more): privileged accounts; non-privileged accounts].
[Withdrawn: Incorporated into IA-2(6).]
Provide a single sign-on capability for [Assignment: organization-defined system accounts and services].
[Withdrawn: Incorporated into IA-2(8).]