GovRAMP releases phishing-resistant MFA requirements guide for Moderate and High impact systems

Original title: Phishing-Resistant MFA in the GovRAMP Security Framework

GovRAMP has released a quick-reference guide outlining phishing-resistant multi-factor authentication requirements for systems classified as Moderate and High impact. The guide specifies applicable authentication assurance levels and lists acceptable authentication methods for compliance. Organizations operating systems at these impact levels must implement phishing-resistant MFA as part of their security controls to meet GovRAMP standards.

What changed

  • GovRAMP published a new quick-reference guide specifically addressing phishing-resistant MFA requirements, providing clarity on implementation for Moderate and High impact systems
  • The guide defines applicable authentication assurance levels for phishing-resistant MFA in GovRAMP's security framework
  • Acceptable authentication methods for phishing-resistant MFA are formally documented in the new resource

What the document requires

GovRAMP requires phishing-resistant multi-factor authentication for systems with Moderate and High impact levels.

Who is affected

Organizations operating systems classified as Moderate or High impact under GovRAMP, including federal agencies and contractors subject to GovRAMP requirements in the US federal government context

Summary generated by a language model; the official text prevails. Not legal advice.