An organization uses biometric authentication for physical access but relies solely on passwords for system access. From a logical access control perspective, what recommendation should an IS auditor make?
-
A
Replace biometrics with passwords for consistency
-
B
Implement multi-factor authentication for system access
-
C
Increase password length requirements only
-
D
Deploy single sign-on to reduce authentication burden