Article 14
|
(Identification and Authentication of Internal Users)
- The information and communication system shall be equipped with a unique function to identify and authenticate internal users of an organization (or processes acting on behalf of organization users), banning the use of joint accounts.
- Multi-factor authentication shall be applied when the administrator account is used to log in a core system through the Internet. Multi-factor authentication is advised for access by internal users to a core system of a type 1 organization.
|