This control requires the use of multifactor authentication (MFA) for two key categories:
All local and network access to privileged accounts
Network access to non-privileged accounts
The goal is to ensure that any account accessing systems—especially those containing Controlled Unclassified Information (CUI)—is protected by strong, layered authentication based on the type and method of access.