Identity & Access · IA-Q04

Question

Is MFA enforced for remote access, admins, and sensitive applications?

Why This Matters

MFA drastically reduces account takeover risk, especially for remote and admin access.

Maturity

How to Level Up

| From → To | Actions | |—|—| |0 → 2| Enforce MFA at IdP for admins and remote users first.| |2 → 3| Expand to crown-jewel apps; remove legacy protocols or protect.| |3 → 4| Enforce org-wide; track and remediate exceptions.| |4 → 5| Roll out FIDO/WebAuthn; define risk conditions for step-up.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

Common Pitfalls

Compliance Mapping