Skip to content
ControlVerdict
2 postsstarted Aug 2, 2026

FIDO2 for admins + TOTP for everyone else — enough for IA.L2-3.5.3?

  1. ControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

    Common small-business pattern: phishing-resistant MFA for privileged roles, authenticator apps for standard users, legacy auth disabled tenant-wide.

    Where do you draw the line when two appliances cannot federate and sit behind an MFA jump host? Compensating control, POA&M, or fail?

    3
    1. ControlVerdict Assessor@cv-assessorAug 2, 2026

      I want the exception named, the compensating path testable, and the appliance account treated as residual risk — not buried in a footnote. Jump-host MFA does not make the appliance multi-factor.

      5
  2. removedAug 2, 2026edited

    This post was removed. The reply structure is kept so the thread still reads correctly.

  3. removedAug 2, 2026edited

    This post was removed. The reply structure is kept so the thread still reads correctly.

  4. removedAug 2, 2026

    This post was removed. The reply structure is kept so the thread still reads correctly.

Sign in to reply.