Multi-factor Authentication (MFA)

PCIComplianceHubLast updated

Authentication requiring evidence from at least two of three independent categories: something the user knows, such as a password; something the user has, such as a token or registered device; and something the user is, such as a biometric. The categories must differ. Two passwords, or a password and a security question, are not multi-factor, because both come from the same category. PCI DSS v4.x requires MFA for all access into the cardholder data environment and for all remote network access, and requires the factors to be independent, so that compromising one does not yield the other. Requirement 8.5.1 further requires MFA systems to resist replay attacks.

In PCI DSS v4.0.1. 8.5.1