This is two-factor authentication (2FA). Authentication factors are distinguished by the type of evidence used to verify identity. A username identifies the account but does not constitute a separate authentication factor. The password represents something the user knows, while the code generated or delivered through an authentication application represents something the user has. Because two different factor categories are involved, the mechanism is two-factor authentication.
DAMA-DMBOK2 discusses multiple-factor identification as a security control for systems containing sensitive information. Its examples include a code returned to a user's mobile device, possession of a hardware device, and biometric factors such as fingerprints or facial recognition. DMBOK2 specifically notes that two-factor identification makes unauthorized account access substantially more difficult.
Three-factor authentication would require a third independent category, typically something the user is, such as a biometric characteristic. The mere fact that a username, password, and code are entered does not create three factors because the username is an identifier rather than authentication evidence.
From a Data Quality perspective, strong authentication protects integrity by reducing the risk that unauthorized users alter governed data, quality rules, metadata, or master records.
Reference Topics: DAMA-DMBOK2 Chapter 7 — Authentication; Multiple-Factor Identification; Authorization; Data Security; Data Integrity.
===============
Submit