Skip to content
arrow_back
search
ISM-1504 policy ASD Information Security Manual (ISM)

Implement Multi-factor Authentication

Users need multiple forms of ID to access sensitive online services, enhancing security.

record_voice_over

Plain language

Multi-factor authentication means using more than just a password to log into important online services. It’s like needing both a key and a swipe card to get into a building. This matters because if someone only needs a password, they could break into your sensitive data if they steal or guess it. Using multiple forms of ID makes it much harder for them to do that.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.
policy ASD Information Security Manual (ISM) ISM-1504
priority_high

Why it matters

Without multi-factor authentication, attackers can use stolen or guessed passwords to access sensitive online services, leading to data theft or unauthorised changes.

settings

Operational notes

Monitor MFA enrolment and failures; remove legacy exceptions; test break-glass access; and review factor strength for sensitive online services.

Mapping detail

Mapping

Direction

Controls