Join our Newsletter — 33% off our NHI Course

CJIS MFA changes: what law enforcement IAM teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

Phishing-resistant MFA is now the real control boundary for CJIS access. The policy shift makes the quality of the authenticator more important than the presence of a second factor. That changes the governance question from "is MFA enabled?" to "can this authentication method withstand phishing and credential replay?" Practitioners should treat authentication strength as the compliance variable, not a feature toggle.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: What is the difference between strong MFA and phishing-resistant MFA?

A: Strong MFA means more than one factor is used, while phishing-resistant MFA means the factor cannot be easily captured and replayed by an attacker. A code sent by text may count as MFA, but it is not resistant enough for high-risk accounts because the secret can be stolen outside the application itself. Resistance is the higher standard.

👉 Read our full editorial: CJIS phishing-resistant MFA raises the bar for identity assurance


This topic was modified 6 hours ago 2 times by NHI Mgmt Group

   
Quote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.