Skip to content
arrow_back
search
E8-MF-ML3.3 bolt ASD Essential Eight

Phishing-resistant multi-factor authentication for data repositories

Use secure multi-factor authentication methods to protect data repositories against phishing attacks.

record_voice_over

Plain language

This control is about making sure that when people access data stored in digital libraries or storage areas, they use a secure form of sign-in that can't be easily tricked by fake requests for their information. Without this, someone could pretend to be them and access sensitive or important data, causing harm or leading to data breaches.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
bolt ASD Essential Eight E8-MF-ML3.3
priority_high

Why it matters

Without phishing-resistant MFA for data repositories, attackers can phish credentials and MFA prompts to access sensitive data and exfiltrate it.

settings

Operational notes

Enforce phishing-resistant MFA (FIDO2/WebAuthn or client certificates) for repository access, disable SMS/OTP, and monitor for repeated MFA prompts and device re-registrations.

Mapping detail

Mapping

Direction

Controls