Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Solution Architect

previous version on gdrive

N.4.10 Applying authentication methods

Control Overview

This control mandates that the organization implements robust identity verification mechanisms that scale dynamically according to the sensitivity of the data or systems being accessed. Under the NIS 2 directive, Multi-Factor Authentication (MFA) is a non-negotiable baseline requirement. It must be strictly applied to all accounts possessing administrative or special privileges, all environments containing sensitive or high-impact corporate/client data, and universally for any user initiating an authenticated session via the public internet.

note

Applicability Note: This control is fully applicable to the anDREa platform and serves as the primary gateway defense protecting cloud tenant data, code repositories, and operational business platforms.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, enforcing an un-bypassable multi-layered identity policy across all operational domains.

anDREa does not rely on single-factor passwords for any public-facing or internal engineering asset. Access control is centralized and hardened across our primary infrastructure nodes: myDRE tenant workspaces, Google Workspace (corporate communications), GitHub (source code management), and Zoho Desk (customer support operations).

To counter modern session-hijacking and adversary-in-the-middle (AiTM) phishing tactics, our technical baseline has been advanced beyond standard notifications. We enforce sophisticated MFA configurations that leverage cryptographic number matching, geolocation verification, and device-app identification. Furthermore, we actively encourage passwordless workflows and FIDO2 hardware security keys (e.g., YubiKeys) for all administrative paths. High-risk account actions, such as administrative credential or MFA resets, cannot be executed autonomously; they require strict, support-team-controlled out-of-band verification.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.05 - Secure authenticationMandates that secure authentication systems are implemented based on access restrictions and the classification of information.
ISO/IEC 27001A.05.15 - Access control, A.05.16 - Identity management, A.05.17 - Authentication informationCore sub-frameworks governing access control rules, centralized identity provisioning, and the secure generation/management of authentication secrets.
Identity EnforcementsConditional Access & MFA Policy RulesLive technical policy configurations (Azure Entra ID / Google Admin) proving forced multi-factor enrollment and number-matching rules for internet logins. (Logon policy)
Source ControlsGitHub Organization Security SettingsAdministrative configuration templates proving mandatory MFA enforcement for all developers and repository contributors.
Operational RecordsSupport Escalation & Reset LogsTicketing logs detailing the dual-custody verification steps executed before resetting an administrative user's MFA tokens.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Universal internet-facing MFA, administrative number-matching baselines, and structured high-risk reset workflows are completely operationalized and enforced across all systems.
  • Continuous Improvement: To align cleanly with modern best practices and impending supervisory audits, formally document an explicit architectural ban on telecom-dependent (SMS-only or Voice-call) MFA fallback options within your master Authentication Information Policy, mandating app-based or hardware-token authentication exclusively.