Skip to content

Access & Identity Policy

Multi-Factor Authentication Policy

Require a second authentication factor for access to sensitive systems.

Summary

Policy overview

Scope

Cloud consoles, source control, email, deployment systems, password management, and any system holding customer information.

Objectives

  • Eliminate single-factor access to administrative systems
  • Prefer phishing-resistant factors where supported
  • Define approved factor types
  • Define recovery handling for lost factors

What the policy covers

  • MFA is required for all administrative and privileged access.
  • Phishing-resistant factors are preferred where available.
  • SMS is not an approved primary factor for administrative access.
  • Recovery codes are stored in managed secret storage.

Governance

MFA enforcement is configured at the platform level. Exceptions require documented approval and a compensating control.

Framework references

  • NIST SP 800-63B
  • CIS Controls 6
  • NIST SP 800-171 3.5.3

These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.

Related

More Access & Identity policies

  • Access Control Policy

    Ensure access to systems and information is granted on the basis of role and business need.

  • Password Policy

    Set requirements for authenticator strength, storage, and handling.

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.