GLOSSARY logo

GLOSSARY

THE TECHNICAL LANGUAGE OF DIGITAL B2B INFRASTRUCTURE

FRAMEWORK
CYBERSECURITY

Two-Factor Authentication (2FA)

Authentication requiring evidence from two distinct factor categories before access is granted.


BUSINESS RELEVANCE

It reduces the likelihood or impact of unauthorised access, data loss and service disruption and provides evidence for assurance.


IMPLEMENTATION EXAMPLE

A cross-functional team applies Two-Factor Authentication (2FA) in a production initiative, defines ownership and success criteria, tests representative scenarios, monitors outcomes and records corrective actions before scaling.


LIMITATIONS

No single control eliminates risk. Misconfiguration, compromised identities, weak recovery and changing threats require defence in depth and continuous review.


TECHNICAL EXPLANATION

Authentication requiring evidence from two distinct factor categories before access is granted. The control should be based on identified threats, least privilege, strong identity, logging, monitoring and tested response procedures. Effectiveness depends on implementation and operating context rather than the presence of a product label.


Secondary Topics

Systems Architecture

Sources

NIST Cybersecurity Framework 2.0 — https://www.nist.gov/cyberframework; OWASP — https://owasp.org/

Related terms

OAuth 2.0

FRAMEWORK
CYBERSECURITY

An open standard authorization framework providing applications secure delegated access to server resources without sharing passwords.

NIST AI Risk Management Framework (AI RMF)

FRAMEWORK
AI GOVERNANCE

A comprehensive US framework providing guidance across Govern, Map, Measure, and Manage functions for trustworthy AI.

Single Sign-On (SSO)

FRAMEWORK
CYBERSECURITY

An authentication framework allowing users to access multiple distinct software applications using a single master credential.

Zero Trust

FRAMEWORK
CYBERSECURITY

A security architecture enforcing strict identity verification, micro-segmentation, and least-privilege access for all network requests.

Role-Based Access Control (RBAC)

FRAMEWORK
CYBERSECURITY

A security mechanism restricting system access permissions strictly according to defined organizational job responsibilities.