Implement Strong Access Control Measures
8
Identify Users and Authenticate Access to System Components
Every user with access to CDE systems must be identified and authenticated. PCI DSS 4.0.1 significantly strengthened this requirement by mandating multi-factor authentication (MFA) for all access to the CDE, increasing minimum password length to 12 characters, and requiring stronger identity management practices.
Control Intent
Ensure individual accountability by assigning a unique identification to each person with computer access, and verify user identity through strong authentication mechanisms including multi-factor authentication for all CDE access.
Common Failures
- MFA not implemented for all access to the CDE — only configured for remote/VPN access
- Passwords shorter than 12 characters or lacking complexity requirements
- Shared or generic administrative accounts used across teams without individual accountability
- Service accounts with overly broad privileges and non-rotating passwords
- Session timeout not enforced or set longer than 15 minutes on CDE systems