Skip to content
arrow_back
search
ISM-1401 policy ASD Information Security Manual (ISM)

Implement Multi-Factor Authentication for Security

Users need to use multiple identification methods to ensure secure access.

record_voice_over

Plain language

Multi-factor authentication means using more than just a password to log into your systems. It's like adding an extra lock on your door – it makes it much harder for someone to sneak in. If you don't have this, a hacker could easily guess or steal a password and access your sensitive information, causing disruptions and potentially financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
policy ASD Information Security Manual (ISM) ISM-1401
priority_high

Why it matters

Without MFA, stolen credentials can grant unauthorised access, enabling account takeover, data breaches and significant business disruption.

settings

Operational notes

Review MFA enrolment and token/app lifecycle, promptly revoke lost factors, and ensure MFA is enforced for remote and privileged access to reduce takeover risk.

Mapping detail

Mapping

Direction

Controls