Requirement 8: Identify users and authenticate access to system components
Every user must be uniquely identified and strongly authenticated, with MFA into the CDE.
Sub-requirements
Processes and mechanisms are defined and understood
2 defined requirementsDocument identification and authentication policy.
View defined requirements →User identification and accounts are managed
8 defined requirementsAssign unique IDs, no shared accounts, and remove access promptly on departure.
View defined requirements →Strong authentication is established and managed
12 defined requirementsEnforce strong authentication factors and protect them in transit and storage.
View defined requirements →MFA is implemented to secure access into the CDE
3 defined requirementsRequire MFA for all access into the CDE and all remote/admin access.
View defined requirements →MFA systems are configured to prevent misuse
1 defined requirementConfigure MFA to resist replay and bypass.
View defined requirements →Application and system accounts are managed
3 defined requirementsControl service-account credentials, rotate them, and avoid interactive use.
View defined requirements →Tips
- ›Phishing-resistant MFA (FIDO2/passkeys) is the gold standard.
- ›Eliminate shared logins, they break unique identification.
Evidence to keep
- ✓Authentication policy
- ✓MFA configuration
- ✓Account provisioning/deprovisioning records
Example
Staff log in via SSO with mandatory MFA, the CDE requires MFA on every entry, and service accounts use rotated secrets in a vault.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.