Skip to content
arrow_back
search
ISM-1874 policy ASD Information Security Manual (ISM)

Phishing-Resistant Multi-Factor Authentication for Customers

Online services use multi-step security to prevent phishing attacks during customer login.

record_voice_over

Plain language

This control is about using multi-step security checks that are hard for scammers to trick when you log in online. It matters because if you don't have these strong checks, someone pretending to be you could get into your accounts and steal your information or money.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
policy ASD Information Security Manual (ISM) ISM-1874
priority_high

Why it matters

Without phishing-resistant MFA, attackers can impersonate customers, leading to significant data breaches and financial losses.

settings

Operational notes

Use phishing-resistant MFA for customers (e.g., FIDO2/WebAuthn passkeys) and monitor for OTP/push fatigue; keep enrolment and recovery guidance current.

Mapping detail

Mapping

Direction

Controls