Organizations and companies must roll out Multi-Factor authentication (MFA) for all non-console related access into their Cardholder Data Environment (CDE) for all staff with administrative access with a deadline of February 1, 2018 according to PCI requirement 8.3.1
- Multi-Factor Authentication (MFA) has to have at least 2/3 of; Something you know, Something you have, Something you are according to requirement 8.2.
- Authentication methods should be independent of one another
- Authenticators should be conveyed through different network channels, with an emphasis on offline abilities.
- All factors in Multi-Factor Authentications have to be verified prior to the authentication mechanism granting access or providing knowledge of the success or failure of any one authenticator.
SAASPASS provides you the ability to comply with PCI DSS 3.2 by enabling MFA to many of your application areas;
- Protecting computer and Server login
- Computer Remote Access (RDP)
- Firewall and VPN access
- Enterprise Cloud applications (supported SAML 2.0)
- Enterprise applications (supported RADIUS)