PCI DSS v4.0: a bite size guide to Multi-Factor Authentication 

To help organisations transition from PCI V3.2.1 to PCI V4.0 and maintain PCI compliance, Securious has developed a series of articles explaining how to implement the evolved requirements of the standard. 

PCI DSS v4.0 has introduced expanded requirements for Multi-Factor Authentication (MFA). MFA is a security mechanism that requires individuals to present two or more verification factors to gain access to a resource such as an application, online account, or a VPN.

These factors typically include something the user knows (password or PIN), something the user has (security token or smartphone app), or something the user is (biometric verification such as fingerprint or facial recognition). 

The purpose of MFA is to create a layered defence that makes it significantly more difficult for an unauthorised person to access a target such as physical location, computing device, network, or database.

Unlike PCI DSS v3.2.1, which primarily mandated MFA for remote access from untrusted networks, PCI DSS V4.0 extends this requirement, making MFA mandatory for all individuals accessing the cardholder data environment (CDE), whether remotely or locally. 

Why the shift to MFA for all access points?

Security breaches are not just about external threats but also involve mitigating risks from within an organisation. Implementing MFA adds an essential layer of security that helps prevent unauthorised access, protecting sensitive payment card information from both external and internal threats.

In the context of protecting cardholder data, MFA plays a crucial role. It significantly reduces the risk of unauthorised access resulting from compromised credentials. By requiring multiple means of identification, MFA decreases the likelihood of successful cyber attacks, which is vital for maintaining the confidentiality and integrity of sensitive payment card information.

What are the dangers of failing to implement MFA?

Not implementing Multi-Factor Authentication (MFA) in environments where cardholder data is processed and stored presents several significant security risks. These dangers are particularly acute given the sensitive nature of payment card information, and the potential financial and reputational damage that can result from a data breach.

Without MFA, the only barrier to entry is typically something the user knows, like a password or PIN. These credentials can be more easily stolen, guessed, or cracked by attackers using a variety of techniques such as phishing, brute force attacks, or through the exploitation of weak or reused passwords.

Once inside the system, an attacker without MFA obstacles can more readily elevate their access privileges. Without the need to authenticate further, they can exploit fewer secure internal systems, potentially gaining administrative access and control over critical systems and sensitive data.

For example, in the Target Corporation Breach (2013), the data from 40 million credit and debit cards was stolen. Attackers gained access through credentials stolen from a third-party vendor, and the absence of MFA allowed them to access Target’s network with fewer obstacles.

What MFA Means for Your Security Strategy

MFA adds complexity to the authentication process but significantly lowers the risk of an attacker accessing sensitive systems, even if they have one set of credentials (such as compromised passwords). 

Here’s how you can implement MFA effectively:

Assessment and Planning

  • Conduct a thorough audit of current security systems and access points to the CDE.
  • Identify all user roles and classify them based on access necessity and level of data sensitivity they handle.
  • Develop an MFA implementation roadmap tailored to the organisational structure and compliance requirements.

Technical Implementation

  • Select Robust MFA Solutions: Choose MFA tools that align with PCI DSS requirements and fit seamlessly with your existing technology stack. Consider factors like user experience, integration capabilities, and the level of security provided.
  • Comprehensive Coverage: Apply MFA to all access points to the CDE, ensuring no entry is left vulnerable, whether it’s through physical terminals, remote access software, or administrative systems.

User Training and Awareness

  • Continuous Education: Train all users on the importance of MFA, focusing on how it protects against data breaches and the role each user plays in maintaining security.
  • Policy Enforcement: Regularly update and enforce security policies that include MFA practices, making it a part of the organisational culture.

Monitoring and Maintenance

  • Monitor MFA implementation to track access and authentication failures and to detect any anomalies that might indicate attempts to bypass security
  • Regularly review and update MFA configurations to adapt to new security challenges or changes in organisational structure.

Compliance and Documentation

  • Document all MFA policies and procedures as required by PCI DSS v4.0.
  • Regularly audit MFA implementation to ensure compliance with the PCI DSS standards and to address any gaps or deficiencies.

To summarise

The importance of MFA cannot be overstated, especially with PCI DSS v4.0’s expanded requirements. While it does not solve all security issues—such as the risk posed by hardcoded passwords — it significantly enhances your defence against unauthorised access. 

Combining MFA with other security practices such as secure password storage and regular security audits creates a robust security framework that can protect your data from the most determined attackers.

If you would like help learning more about how MFA can protect your business and help you achieve PCI V4 compliance, please get in touch with Securious using the contact form below.