Implement strong access control measures

Requirement 8: Identify users and authenticate access to system components

Every user must be uniquely identified and strongly authenticated, with MFA into the CDE.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 8 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • Phishing-resistant MFA (FIDO2/passkeys) is the gold standard.
  • Eliminate shared logins, they break unique identification.

Evidence to keep

  • Authentication policy
  • MFA configuration
  • Account provisioning/deprovisioning records

Example

Staff log in via SSO with mandatory MFA, the CDE requires MFA on every entry, and service accounts use rotated secrets in a vault.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map