Changes · Policy · occurred Mar 1, 2026

MFA policy updated to include hardware tokens

Closed

Description

Acceptable MFA methods policy expanded to require FIDO2 hardware tokens for all privileged users accessing CUI systems. Mobile authenticators still permitted for standard users.

Related requirements

Requirements

Decision

Decision record
FieldValue
OutcomeNo impact
RationalePolicy tightening only; no scope or boundary changes. Affirmation strengthened.
Scope update requiredNo
Decided byMarcus Webb

History

  1. Change logged

    MFA policy updated to include hardware tokens was recorded.

    Marcus Webb

  2. Decision recorded

    No impact

    Marcus Webb