Skip to content
arrow_back
search
ISM-1872 policy ASD Information Security Manual (ISM)

Ensuring Phishing-Resistant Multi-Factor Authentication

Users must use multi-factor authentication that resists phishing when accessing online services.

record_voice_over

Plain language

This control is about using safe extra steps, like a special phone app or a security key, to access online services without falling for fake login tricks. If you don't have these protections, someone could pretend to be you and access your sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Multi-factor authentication used for authenticating users of online services is phishing-resistant.
policy ASD Information Security Manual (ISM) ISM-1872
priority_high

Why it matters

Without phishing-resistant MFA, attackers can use fake sign-in pages to steal factors and gain unauthorised access, causing data breaches.

settings

Operational notes

Prefer FIDO2/WebAuthn passkeys or security keys; disable OTP/SMS for logins, and regularly validate MFA flows against phishing simulations.

Mapping detail

Mapping

Direction

Controls