Skip to content
arrow_back
search
ISM-1681 policy ASD Information Security Manual (ISM)

Mandating Multi-Factor Authentication for Customer Services

Customers must use multi-factor authentication when accessing sensitive online services.

record_voice_over

Plain language

This control requires using more than just a password to access online services that handle sensitive data. It's essential because passwords can be easily stolen or guessed, which can lead to unauthorised access to customer information and potential financial and reputational losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
policy ASD Information Security Manual (ISM) ISM-1681
priority_high

Why it matters

Without MFA, customer logins can be compromised via password theft and credential stuffing, exposing sensitive customer data and damaging trust.

settings

Operational notes

Enforce MFA for all customer logins to services handling sensitive data; monitor auth failures for stuffing, and periodically review MFA method strength and enrolment coverage.

Mapping detail

Mapping

Direction

Controls