Skip to content
arrow_back
search
ISM-1505 policy ASD Information Security Manual (ISM)

Implement Multi-factor Authentication for Data Repositories

Require multi-factor authentication for accessing data storage to enhance security.

record_voice_over

Plain language

This control means that when people try to access your important data storage systems, they have to pass an extra layer of security called multi-factor authentication. It matters because if someone steals a password, this extra step can prevent them from getting into your systems and stealing sensitive information or causing other harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication is used to authenticate users of data repositories.
policy ASD Information Security Manual (ISM) ISM-1505
priority_high

Why it matters

Without MFA for data repositories, stolen credentials can enable unauthorised access to sensitive data, causing breach, disruption and reputational harm.

settings

Operational notes

Monitor repository sign-in and MFA logs for failures or anomalies; enforce enrolment, test MFA regularly, and promptly remediate accounts not using MFA.

Mapping detail

Mapping

Direction

Controls