What is requirement 8.4.2?

Take a quick look at the image to the left—that was me a while back, realizing mid-audit about this new MFA requirement

If you’re sitting there thinking, "We already have MFA on our VPN, so we’re good," let’s pause. This specific control is currently catching dozens of IT and security teams off guard.

Let's break down what Requirement 8.4.2 actually demands, why your current setup might fail, and how to protect your CDE before your QSA sits down for your next audit.

The Terminology Breakdown

Subscribe to keep reading

This content is free, but you must be subscribed to GRC Driven to continue reading.

Already a subscriber?Sign in.Not now

Reply

Avatar

or to participate

Keep Reading