Two-Factor Authentication (2FA)
Authentication requiring evidence from two distinct factor categories before access is granted.
It reduces the likelihood or impact of unauthorised access, data loss and service disruption and provides evidence for assurance.
A cross-functional team applies Two-Factor Authentication (2FA) in a production initiative, defines ownership and success criteria, tests representative scenarios, monitors outcomes and records corrective actions before scaling.
No single control eliminates risk. Misconfiguration, compromised identities, weak recovery and changing threats require defence in depth and continuous review.
Authentication requiring evidence from two distinct factor categories before access is granted. The control should be based on identified threats, least privilege, strong identity, logging, monitoring and tested response procedures. Effectiveness depends on implementation and operating context rather than the presence of a product label.
Systems Architecture
NIST Cybersecurity Framework 2.0 — https://www.nist.gov/cyberframework; OWASP — https://owasp.org/
