N.4.10 Applying authentication methods
Control Overview
This control mandates that the organization implements robust identity verification mechanisms that scale dynamically according to the sensitivity of the data or systems being accessed. Under the NIS 2 directive, Multi-Factor Authentication (MFA) is a non-negotiable baseline requirement. It must be strictly applied to all accounts possessing administrative or special privileges, all environments containing sensitive or high-impact corporate/client data, and universally for any user initiating an authenticated session via the public internet.
Applicability Note: This control is fully applicable to the anDREa platform and serves as the primary gateway defense protecting cloud tenant data, code repositories, and operational business platforms.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, enforcing an un-bypassable multi-layered identity policy across all operational domains.
anDREa does not rely on single-factor passwords for any public-facing or internal engineering asset. Access control is centralized and hardened across our primary infrastructure nodes: myDRE tenant workspaces, Google Workspace (corporate communications), GitHub (source code management), and Zoho Desk (customer support operations).
To counter modern session-hijacking and adversary-in-the-middle (AiTM) phishing tactics, our technical baseline has been advanced beyond standard notifications. We enforce sophisticated MFA configurations that leverage cryptographic number matching, geolocation verification, and device-app identification. Furthermore, we actively encourage passwordless workflows and FIDO2 hardware security keys (e.g., YubiKeys) for all administrative paths. High-risk account actions, such as administrative credential or MFA resets, cannot be executed autonomously; they require strict, support-team-controlled out-of-band verification.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.05 - Secure authentication | Mandates that secure authentication systems are implemented based on access restrictions and the classification of information. |
| ISO/IEC 27001 | A.05.15 - Access control, A.05.16 - Identity management, A.05.17 - Authentication information | Core sub-frameworks governing access control rules, centralized identity provisioning, and the secure generation/management of authentication secrets. |
| Identity Enforcements | Conditional Access & MFA Policy Rules | Live technical policy configurations (Azure Entra ID / Google Admin) proving forced multi-factor enrollment and number-matching rules for internet logins. (Logon policy) |
| Source Controls | GitHub Organization Security Settings | Administrative configuration templates proving mandatory MFA enforcement for all developers and repository contributors. |
| Operational Records | Support Escalation & Reset Logs | Ticketing logs detailing the dual-custody verification steps executed before resetting an administrative user's MFA tokens. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Universal internet-facing MFA, administrative number-matching baselines, and structured high-risk reset workflows are completely operationalized and enforced across all systems.
- Continuous Improvement: To align cleanly with modern best practices and impending supervisory audits, formally document an explicit architectural ban on telecom-dependent (SMS-only or Voice-call) MFA fallback options within your master Authentication Information Policy, mandating app-based or hardware-token authentication exclusively.