The PCI compliance multi factor authentication dea
Post# of 82672
"PCI requirement 8.3.1 states that organizations must incorporate multi-factor authentication for all non-console access into the cardholder data environment (CDE) for personnel with administrative access by January of 2018. "
"MFA requires at least two of the three methods described in requirement 8.2: Something you know, Something you have, Something you areAuthentication methods should be independent of one another (ie. one authenticator shouldn’t give you access to the second authenticator)Authenticators should be conveyed through different network channels (i.e. out-of-band authentication)All factors in MFA are verified prior the authentication mechanism granting access or providing knowledge of the success or failure of any one authenticator."