Skip to content
arrow_back
search
ISM-1873 policy ASD Information Security Manual (ISM)

Enhance Security with Phishing-Resistant MFA

Online services should use multi-factor authentication that cannot be easily tricked by phishing.

record_voice_over

Plain language

Phishing-resistant multi-factor authentication is a way to double-check that you are who you say you are when accessing online services. This is important because regular passwords can be easily stolen or guessed, leading to fraud or data breaches, while phishing-resistant methods are much harder for attackers to bypass.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
policy ASD Information Security Manual (ISM) ISM-1873
priority_high

Why it matters

Without phishing-resistant MFA for customer logins, phished credentials and OTPs can be replayed, enabling account takeover and data breaches.

settings

Operational notes

Offer phishing-resistant MFA (FIDO2/WebAuthn/passkeys) for customer logins; disable SMS/OTP-only flows where possible and monitor for MFA fatigue/replay.

Mapping detail

Mapping

Direction

Controls