Skip to content
arrow_back
search
ISM-1173 policy ASD Information Security Manual (ISM)

Use Multi-Factor Authentication for Privileged Users

Privileged users must verify their identity using multiple forms of identification to log into systems.

record_voice_over

Plain language

Multi-factor authentication means using more than one way to prove who you are when logging into systems, especially for users who can access important areas. This is crucial because if hackers steal a single password, they could cause significant damage by accessing sensitive information, misusing data, or even shutting down systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate privileged users of systems.
policy ASD Information Security Manual (ISM) ISM-1173
priority_high

Why it matters

Without MFA for privileged users, a stolen password can enable admin access, leading to system compromise, data loss, and service disruption.

settings

Operational notes

Enforce MFA for all privileged accounts, regularly test MFA login flows, and ensure administrators can use and recover MFA tokens without bypasses.

Mapping detail

Mapping

Direction

Controls