Skip to content
arrow_back
search
ISM-0590 policy ASD Information Security Manual (ISM)

Ensure Strong Authentication for Multi-Function Devices

Multi-function devices should have security measures as strong as those for computers they connect to.

record_voice_over

Plain language

Multi-function devices, like printers that also scan or fax, need the same strong security protections as the computers they connect to. If these devices are not properly secured, hackers could potentially access the network through them, leading to data leaks or other security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.
policy ASD Information Security Manual (ISM) ISM-0590
priority_high

Why it matters

If MFD authentication is weaker than workstation controls, attackers can access scan shares and admin consoles to pivot, exfiltrate data and disrupt services.

settings

Operational notes

Configure MFD logon to match workstation auth (e.g., AD/LDAP + MFA where used); disable defaults, audit access, and keep credentials/policies aligned.

Mapping detail

Mapping

Direction

Controls