Risk-informed Use of Multi-Factor Authentication Function
Parent: GR
Description
The mission should provide the capability for each system owner to implement Multi- Factor Authentication of a specific level of assurance.
Mapped SPARTA techniques
5 techniques
Ground system compromise most often begins with a credential, and multi-factor authentication at a defined assurance level interdicts the reuse of a stolen one. Moderate because the practice is risk-informed and per-system-owner, so coverage is a mission decision rather than a guarantee. [Curation] Multi-factor authentication interdicts the credential route into a ground system, but IA-0007 spans operator workstations, mission control software, scheduling and orchestration services, front-end processors and station controllers, reached by exploitation and supply chain as well as by credentials. One vector of several, so addresses.
Traversal by reusing legitimate credentials is what a second factor breaks, since the reused secret alone no longer authenticates.
Long-lived presence in ground infrastructure is established before the factor is challenged again, so multi-factor authentication governs the re-entry path rather than the residency.
Credentialed persistence survives a second factor where the adversary holds a session or a service account outside the interactive login path, so the practice narrows the technique without closing it.
Gathering valid credentials has value only while a credential is sufficient to authenticate. A second factor devalues the reconnaissance outcome directly. [Curation] REC-0003.04 is the gathering of valid credentials. Multi-factor authentication devalues what the adversary collects but does nothing to impede the collection, and the corpus places mitigates on 3 of 14,424 reconnaissance edges, which is a rule this would break. Recorded at addresses.
Cite as SafeMode Space, nasa-bpg GR-MFA-01.