H6.12
Multi-factor Authentication
Cards in this group · 4
- H6.12.1MFA should offer strength options between convenience and security
- H6.12.2A failed second factor needs a pre-enrolled backup method
- H6.12.3Assess device availability before mandating MFA
- H6.12.4Recovery-code custody must be explained to the person who holds them