8.3.1 All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you
All user access to system components for users and administrators is authenticated via at least one of the following authentication factors: • Something you know, such as a password or passphrase. • Something you.
5
artefacts
1
held by a system
2
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- For each type of authentication factor, observation or configuration evidence that access is authenticated using it · Identity provider / directory
periodic reviewEvidence produced at each review
- Evidence no access path permits access without authentication · Identity provider / directory
- Records for non-console and console access alike · Identity provider / directory
governing documentDocuments that govern the control
- Documentation describing the authentication factors used for user and administrator access to system components · Policy repository / GRC workspace
- Inventory of in scope system components and the authentication method for each · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Identity provider / directory on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Authentication enforced on the main path while a management interface, API or legacy port allows unauthenticated access
- Certificates or keys used as the factor with no control over their distribution, weakening the something you have claim
- Component inventory incomplete, so a component authenticating differently is never assessed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.2.8 Session idle timeout · 8.3.2 Strong cryptography is used to render all authentication factors unreadable during transmission and storage on all system components