Skip to content

Commit

Permalink
CMP-2460: Reqs 8.4 and 8.5 are not applicable
Browse files Browse the repository at this point in the history
  • Loading branch information
yuumasato committed Jul 11, 2024
1 parent f22ea82 commit 5264dfa
Showing 1 changed file with 6 additions and 9 deletions.
15 changes: 6 additions & 9 deletions controls/pcidss_4_ocp4.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2331,9 +2331,7 @@ controls:
- base
status: not applicable
notes: |-
This parent requirement does not set one specific combination of Multi-factor authentication
(MFA), so we can't enforce the use of smartcards or any specific solution. The systems
usually support MFA but the chosen solution depends on site policies.
Multi-factor authenticators are managed externally to OpenShift by the identity provider
controls:
- id: 8.4.1
title: MFA is implemented for all non-console access into the CDE for personnel with
Expand All @@ -2355,13 +2353,15 @@ controls:
entity's network that could access or impact the CDE.
levels:
- base
status: pending
status: not applicable

- id: '8.5'
title: Multi-factor authentication (MFA) systems are configured to prevent misuse.
levels:
- base
status: pending
status: not applicable
notes: |-
Multi-factor authenticators are managed externally to OpenShift by the identity provider
controls:
- id: 8.5.1
title: MFA systems are properly implemented.
Expand All @@ -2374,10 +2374,7 @@ controls:
- Success of all authentication factors is required before access is granted.
levels:
- base
status: pending
notes: |-
Each site might have a different MFA solution and each solution has its own capabilities.
This requirement demands manual assessment based on site policies.
status: not applicable

- id: '8.6'
title: Use of application and system accounts and associated authentication factors is
Expand Down

0 comments on commit 5264dfa

Please sign in to comment.