Skip to content
arrow_back
search
ISM-1502 policy ASD Information Security Manual (ISM)

Ensure Multi-factor Authentication for Online Services

Use two or more forms of identity verification to access sensitive data online.

record_voice_over

Plain language

Multi-factor authentication is like having a double lock on your door. It means that to access your sensitive data online, you need to prove your identity in two or more different ways. This is important because if a hacker gets hold of your password, they still can’t get in without the second piece of evidence, keeping your valuable information safe from prying eyes.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.
policy ASD Information Security Manual (ISM) ISM-1502
priority_high

Why it matters

Failing to block external emails spoofing internal domains can enable phishing and BEC, leading to credential theft, data breaches, and compromised systems.

settings

Operational notes

Configure the gateway to block inbound external mail using internal domains/subdomains in the From address; review exceptions, and monitor logs for spoof attempts and rule drift.

Mapping detail

Mapping

Direction

Controls