Authentication

PCIComplianceHubLast updated

Proving that the account attempting access belongs to the person, device or process claiming it, by presenting one or more authentication factors: something known, something held, or something the claimant is. PCI DSS requires it for every access to an in-scope system component and requires two or more factor types for administrative access into the CDE and for all remote access. It answers who; authorisation, which follows it, answers what they may do.