Skip to content
arrow_back
search
ISM-1683 policy ASD Information Security Manual (ISM)

Central Logging of Multi-factor Authentication Events

Multi-factor authentication attempts, whether they succeed or not, are logged together in a central system.

record_voice_over

Plain language

This control is about making sure that all attempts to log in with extra security steps, whether successful or not, are recorded in one place. It's important because if there is suspicious activity, these records help us understand what happened so we can respond quickly and protect against security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Successful and unsuccessful multi-factor authentication events are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1683
priority_high

Why it matters

Without central MFA event logging, failed and successful authentication attempts may be missed, delaying detection of account compromise.

settings

Operational notes

Centrally log all successful and failed MFA events from all systems; review and protect logs weekly to detect abnormal patterns.

Mapping detail

Mapping

Direction

Controls