Skip to content
arrow_back
search
ISM-1682 policy ASD Information Security Manual (ISM)

Enhance User Security with Phishing-resistant MFA

Multi-factor authentication protects systems by not relying solely on passwords, reducing phishing risks.

record_voice_over

Plain language

Phishing-resistant multi-factor authentication is about adding extra layers of security to prevent unauthorised access to systems, especially from deceptive attacks like phishing, where someone tricks you into giving away your login details. This is crucial because if systems are only protected by passwords, which can be easily stolen, there's a higher risk of data breaches and loss of important information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Multi-factor authentication used for authenticating users of systems is phishing-resistant.
policy ASD Information Security Manual (ISM) ISM-1682
priority_high

Why it matters

Without phishing-resistant MFA, attackers can exploit MFA fatigue, intercept OTPs, or use real-time phishing to access sensitive systems.

settings

Operational notes

Use FIDO2/WebAuthn (passkeys or security keys) for sign-in. Disable SMS/OTP fallbacks and require phishing-resistant methods for all users.

Mapping detail

Mapping

Direction

Controls