A second verification step beyond password is required to access critical systems
Requiring a second factor on email, the identity platform and systems holding important data is a specific access control rule A.5.15 asks organisations to enforce based on business need.
Requiring a second authentication factor is a control on how authentication itself is verified, one of the concrete safeguards A.5.17 asks organisations to put around credentials.
This policy facet requires a second authentication factor for email, the identity platform, remote access and every system holding important data, the written commitment A.8.5 asks for.