DroneUp Compliance Docs

CBI // INFORMATION SECURITY · Document ID: DU-2-SUB-717-007 · Classification: CBI

Multi-Factor Authentication (MFA) Subpolicy

DU-2-SUB-717-007 · owner: infosec · QMS clause: 07.01.07

Confidential Business Information (CBI) — do not distribute. This document contains proprietary information of DroneUp, LLC. It is intended solely for the information and use of parties operating on behalf of DroneUp, LLC and its affiliates. Such proprietary information may not be used, reproduced, or disclosed to any other parties for any other purpose without express written permission. The information contained in this document is effective as of the revision date in the document control record.

Revision history

VersionDateDescriptionUpdated by
12026-06-19Initial publication.Irina Prozhoha

1. Purpose

This subpolicy defines the mandatory requirements for multi-factor authentication, replay-resistant authentication, and re-authentication across DroneUp systems. It operationalizes the Identification and Authentication Policy [DU-1-POL-717-002].

2. Scope

This Multi-Factor Authentication (MFA) Subpolicy [DU-2-SUB-717-007] operates under the authority of the Identification and Authentication Policy [DU-1-POL-717-002], which is itself subordinate to the Information Security Program Policy [DU-1-POL-521-001]. This subpolicy establishes the mandatory rules for MFA enrollment, permitted authentication factors, replay resistance, and the circumstances requiring re-authentication. The following documents support its implementation:

  • Authenticator Management Subpolicy [DU-2-SUB-717-009]
  • Failed Login Subpolicy [DU-3-SUB-710-138]
  • Identity Management Profiles Subpolicy [DU-2-SUB-717-008]
  • Connectivity and Mobility Subpolicy [DU-2-SUB-717-004]

Who this applies to: all DroneUp employees, contractors, and consultants, and all processes acting on their behalf.

What this covers: all DroneUp information systems, devices, applications, and accounts that create, receive, process, store, or transmit information on behalf of DroneUp, or information entrusted to DroneUp by clients, partners, suppliers, or the U.S. Government, regardless of hosting model.

Review and update this subpolicy at least annually and upon Significant Change, in accordance with the document control record. Non-compliance may result in disciplinary action up to and including termination, as defined in Section 7. Direct questions to the Information Security team through designated support channels.

Compliance and control framework alignment

This subpolicy is designed to address the Identification and Authentication control family (03.05) of NIST SP 800-171 Rev. 3 — specifically Multi-Factor Authentication (03.05.03), Replay-Resistant Authentication (03.05.04), and the re-authentication requirements of User Identification and Authentication (03.05.01). The specific requirements addressed are recorded in the control mapping for this document.

3. Multi-Factor Authentication

Information Systems Personnel shall:

  • Require multi-factor authentication through the centrally managed identity provider for access to all privileged and non-privileged accounts, and prohibit single-factor authentication to DroneUp systems, in accordance with the Identification and Authentication Policy [DU-1-POL-717-002].
  • Configure the identity provider to block account use until enrollment of all required security factors is complete at initial account activation, applying this enforcement to employees, contractors, and sponsored vendor accounts alike, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009].
  • Permit only a password combined with one of the following second factors — authenticator-app push, authenticator-app time-based one-time password (TOTP), device-bound passwordless authentication, or a FIDO2/WebAuthn passkey — prohibit SMS and voice-call factors, and prefer phishing-resistant factors, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009].
  • Require that the additional factor be provided by a device separate from the system gaining access, and that the device comply with the Acceptable Use Policy [DU-2-POL-710-001] and the Connectivity and Mobility Subpolicy [DU-2-SUB-717-004].
  • Require multi-factor authentication for non-organizational users and processes acting on their behalf before granting access to DroneUp systems, in accordance with the Identity Management Profiles Subpolicy [DU-2-SUB-717-008].
  • Require applications and services to authenticate users exclusively through the centrally managed identity provider, and prohibit local application accounts that bypass multi-factor authentication absent a written security exception approved under Section 6, in accordance with the Identification and Authentication Policy [DU-1-POL-717-002].

Information Systems Personnel shall also require All Personnel to:

  • Enroll and maintain the required authentication factors on a device that complies with the Acceptable Use Policy [DU-2-POL-710-001], and protect those factors from loss, sharing, or unauthorized use, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009].
  • Never share authentication factors, one-time codes, or push approvals with any other person, and approve a multi-factor prompt only for a login they personally initiated, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009].
  • Report a lost, stolen, or suspected-compromised authenticator to Information Systems Personnel through designated support channels without delay, in accordance with the Event Response Plan [DU-3-WI-940-002].

4. Replay Resistance

Information Systems Personnel shall:

  • Configure the centrally managed identity provider to use replay-resistant authentication for all user logins to both privileged and non-privileged accounts — including challenge-nonce protocols, time-limited one-time codes, and cryptographically protected authentication exchanges — and permit no login flow to fall back to a replay-able mechanism, in accordance with the Identification and Authentication Policy [DU-1-POL-717-002].
  • Configure the centrally managed identity provider to bind administrative console sessions to both the originating IP address and the originating autonomous system, terminate the session and force re-authentication when either changes mid-session, and verify that both bindings remain enabled, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009].
  • Implement replay-resistant authentication for access to privileged accounts and to non-privileged accounts alike, in accordance with the Replay-Resistant Authentication Procedure [DU-2-PRO-717-018].

5. Re-Authentication

Information Systems Personnel shall require users to re-authenticate in the following circumstances, which constitute the re-authentication conditions referenced in Section 3 of the Identification and Authentication Policy [DU-1-POL-717-002]:

  • At the end of the maximum session lifetime, requiring re-authentication with a password at least every eight (8) hours, and after the inactivity timeout defined in the Access Control Policy [DU-1-POL-717-001].
  • When an authenticator changes, or when a user’s role, privilege level, or group membership changes, in accordance with the Identification and Authentication Policy [DU-1-POL-717-002].
  • Before execution of privileged functions, requiring a fresh factor challenge (step-up authentication) for administrative console access; and, for cloud infrastructure where no standing privileged access exists, requiring users to request time-bound elevated access through the defined access request process, with grants expiring automatically after two (2) hours and further privileged work requiring a new authenticated request, in accordance with the Access Control Policy [DU-1-POL-717-001].
  • After account lockout caused by exceeding failed login limits, in accordance with the Failed Login Subpolicy [DU-3-SUB-710-138].

6. Exceptions

Exceptions to this subpolicy are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].

7. Enforcement and Sanctions

Enforcement and sanctions are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].

Document control

Document numberDU-2-SUB-717-007
TitleMulti-Factor Authentication (MFA) Subpolicy
ClassificationCBI
OwnerVP of Operations
Approval authorityAccountable Security Authority
Effective date2026-06-24
Revision1
Review cycleAnnual; and upon Significant Change
Parent documentDU-1-POL-717-002
CBI // INFORMATION SECURITY · Document ID: DU-2-SUB-717-007 · Classification: CBI