Skip to content
arrow_back
search
ISM-0974 policy ASD Information Security Manual (ISM)

Implement Multi-factor Authentication for User Access

Unprivileged system users must use multi-factor authentication to log in to enhance security.

record_voice_over

Plain language

Using multiple ways to verify your identity, like a password and a code sent to your phone, adds an extra layer of security when logging into systems. This matters because if someone steals your password, they still can't get in without that second piece of verification, helping to protect your information from cyber criminals.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate unprivileged users of systems.
policy ASD Information Security Manual (ISM) ISM-0974
priority_high

Why it matters

Without MFA, stolen credentials can enable unauthorised access, increasing the likelihood of account takeover and sensitive data compromise.

settings

Operational notes

Enforce MFA enrolment for all unprivileged users, review exclusions, and regularly audit accounts to confirm MFA remains enabled and effective.

Mapping detail

Mapping

Direction

Controls