Skip to content
arrow_back
search
ISM-1679 policy ASD Information Security Manual (ISM)

Use Multi-factor Authentication for Third-party Services

Use multiple verification steps for accessing external services with sensitive data.

record_voice_over

Plain language

Using more than one check to log into services that handle your sensitive data is called multi-factor authentication. It matters because it makes it much harder for someone to break into your accounts and steal your important information, especially if they manage to get hold of your password.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.
policy ASD Information Security Manual (ISM) ISM-1679
priority_high

Why it matters

Without multi-factor authentication, unauthorised access to third-party services could expose sensitive data and enable compromise or espionage.

settings

Operational notes

Regularly verify MFA is enforced for all third-party accounts, and reassess supported factors after vendor changes to address new threats.

Mapping detail

Mapping

Direction

Controls