Access & Identity Policy
Multi-Factor Authentication Policy
Require a second authentication factor for access to sensitive systems.
Summary
Policy overview
Scope
Cloud consoles, source control, email, deployment systems, password management, and any system holding customer information.
Objectives
- Eliminate single-factor access to administrative systems
- Prefer phishing-resistant factors where supported
- Define approved factor types
- Define recovery handling for lost factors
What the policy covers
- MFA is required for all administrative and privileged access.
- Phishing-resistant factors are preferred where available.
- SMS is not an approved primary factor for administrative access.
- Recovery codes are stored in managed secret storage.
Governance
MFA enforcement is configured at the platform level. Exceptions require documented approval and a compensating control.
Framework references
- NIST SP 800-63B
- CIS Controls 6
- NIST SP 800-171 3.5.3
These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.
Related
More Access & Identity policies
Access Control Policy
Ensure access to systems and information is granted on the basis of role and business need.
Password Policy
Set requirements for authenticator strength, storage, and handling.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.
Requesting security documentation?
Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.