Define the expected outcome—requires independent authentication factors so a stolen password alone is insufficient—and test it with realistic scenarios. Record the owner, scope, evidence, exceptions and review date. Combine technical testing with operational confirmation so a configured control is not mistaken for an effective control.CIS Critical Security Controls v8: https://www.cisecurity.org/controls/v8