Changes · Policy · occurred Mar 1, 2026
MFA policy updated to include hardware tokens
Closed
Description
Acceptable MFA methods policy expanded to require FIDO2 hardware tokens for all privileged users accessing CUI systems. Mobile authenticators still permitted for standard users.
Related requirements
Requirements
Decision
| Field | Value |
|---|---|
| Outcome | No impact |
| Rationale | Policy tightening only; no scope or boundary changes. Affirmation strengthened. |
| Scope update required | No |
| Decided by | Marcus Webb |
History
Change logged
MFA policy updated to include hardware tokens was recorded.
Marcus Webb
Decision recorded
No impact
Marcus Webb