- This topic has 4 replies, 3 voices, and was last updated 3 years, 11 months ago by .
-
Topic
-
IA-2(3) states the following –
The information system implements multifactor authentication for network access to non-privileged accounts. (3) IDENTIFICATION AND AUTHENTICATION | LOCAL ACCESS TO PRIVILEGED ACCOUNTSWith this in mind I assume the control makes no distinction between Local Area Access (local network access from within the same IS system) or network access coming in from external networks. Is the assumption correct that you would apply the same measure of Multifactor Authentication to either scenario?
Thank You!
You must be logged in to reply to this topic.