Skip to content
arrow_back
search
ISM-1680 policy ASD Information Security Manual (ISM)

Use Multi-Factor Authentication for Online Services

Users must use multi-factor authentication for online services handling non-sensitive data.

record_voice_over

Plain language

This control is about adding an extra layer of security when logging into online services that handle your organisation's non-sensitive data. Even if your password gets stolen, multi-factor authentication makes it much harder for someone to break into your accounts. Without it, cybercriminals could access your data, impersonate you, or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.
policy ASD Information Security Manual (ISM) ISM-1680
priority_high

Why it matters

Without MFA on third-party online services, stolen passwords can enable unauthorised access, leading to data breaches, fraud and reputational damage.

settings

Operational notes

Ensure MFA is enabled and enforced for all users (especially admins) on each third-party online service; regularly review enrolment, exceptions and access logs.

Mapping detail

Mapping

Direction

Controls