Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SOCI 8B and 8C: is your MFA model ready for isolation?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Australia’s updated SOCI rules now require phishing-resistant authentication, least privilege, and access review capability that continues to work for up to 90 days in isolated critical infrastructure environments, according to RSA Security’s analysis. The governance shift is bigger than MFA selection: cloud-only identity assumptions no longer satisfy resilience, recovery, or audit expectations.

NHIMG editorial — based on content published by RSA Security: Multi-Factor Authentication Addressing SOCI 8B and 8C Obligations for Critical Infrastructure

By the numbers:

Questions worth separating out

Q: What breaks when cloud-only MFA is used for isolated critical infrastructure?

A: Cloud-only MFA breaks the continuity of identity assurance when the environment is disconnected.

Q: Why does SOCI 8C make least privilege a recovery issue?

A: Because lateral movement risk rises during isolation and rebuild, when privileged access can expand the blast radius of compromise.

Q: How can security teams tell whether their phishing-resistant MFA model is actually compliant?

A: They need to test whether the authenticators, directories, and policy services remain available without external cloud access and still support the required user and admin flows.

Practitioner guidance

  • Map every authentication dependency to isolation behaviour Document whether MFA, directory, and governance services still operate when cloud connectivity is removed for up to 90 days.
  • Re-test phishing-resistant MFA against OT recovery conditions Validate that phishing-resistant authentication works for privileged, unprivileged, and remote access paths when critical infrastructure is segmented or air-gapped.
  • Rebuild access review for lateral movement resistance Tie access certification to the accounts that can reach critical systems during restoration.

What's in the full article

RSA Security's full post covers the operational detail this post intentionally leaves for the source:

  • The clause-by-clause mapping of SOCI 8B and 8C obligations to identity and governance controls.
  • The specific deployment model for phishing-resistant MFA in on-premises, air-gapped, and semi air-gapped environments.
  • The access review and least-privilege implications for critical systems during recovery and isolation.
  • The practical rationale behind hybrid failover for maintaining authentication during cloud outages.

👉 Read RSA Security’s analysis of SOCI 8B and 8C identity obligations for critical infrastructure →

SOCI 8B and 8C: is your MFA model ready for isolation?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Identity controls designed for connected environments fail when regulation assumes isolation. SOCI 8B and 8C make a simple point that many IAM programmes have avoided: authentication is not complete unless it survives the disconnected state. The governance assumption that cloud services are always available is no longer acceptable in high-risk critical infrastructure. Practitioners should treat survivable identity control as a design constraint, not an exception path.

A few things that frame the scale:

A question worth separating out:

Q: Which controls matter most when a critical infrastructure environment is being restored after compromise?

A: Authentication continuity, least privilege, and access review matter most because recovery is when identity weaknesses become operationally visible. Teams need controls that keep users authenticated, restrict lateral movement, and prove entitlement scope while rebuild work is underway. That is the governance model SOCI is pushing toward.

👉 Read our full editorial: SOCI 8B and 8C turn MFA into an isolation requirement



   
ReplyQuote
Share: