Skip to contentSkip to content
Implement Strong Access Control Measures
8

Identify Users and Authenticate Access to System Components

Every user with access to CDE systems must be identified and authenticated. PCI DSS 4.0.1 significantly strengthened this requirement by mandating multi-factor authentication (MFA) for all access to the CDE, increasing minimum password length to 12 characters, and requiring stronger identity management practices.

Control Intent

Ensure individual accountability by assigning a unique identification to each person with computer access, and verify user identity through strong authentication mechanisms including multi-factor authentication for all CDE access.

Common Failures

  • MFA not implemented for all access to the CDE — only configured for remote/VPN access
  • Passwords shorter than 12 characters or lacking complexity requirements
  • Shared or generic administrative accounts used across teams without individual accountability
  • Service accounts with overly broad privileges and non-rotating passwords
  • Session timeout not enforced or set longer than 15 minutes on CDE systems