← Home

Multi-Factor Authentication (MFA)

Multi-factor authentication (MFA) requires two or more independent factors to verify a person, device or system before granting access. In Industrial Automation and Control Systems (IACS), MFA is especially important for remote access, privileged interactive logins and other high-consequence paths into the Automation Solution.

Teaching note: Paraphrased for learning from IACS cybersecurity course material and ISA/IEC 62443 practice. Not a substitute for the normative text of ISA/IEC 62443 or site identity policy.

Related: IEC 62443-3-1 Clause 5 Authentication | USER 1.9 – Multifactor authentication | FR 1 / SR 1.1 | Secure Remote Access | IEC 62443-3-1 Clause 7.3 VPN | Jump Host | Active Directory | Digital Certificates


Authentication factors

Employ two or more of the following when determining authenticity:

Factors must be independent: compromising one should not automatically compromise another.


Why MFA matters in OT


ISA/IEC 62443 expectations

Map MFA requirements into the Cybersecurity Requirements Specification (CRS) and verify them during CFAT / CSAT.


OT design tips


Key takeaways