Skip to content
arrow_back
search
ISM-1892 policy ASD Information Security Manual (ISM)

Implement Multi-factor Authentication for Customer Services

Use multi-factor authentication to protect access to sensitive customer data online.

record_voice_over

Plain language

Using multi-factor authentication is like having a double lock on your online services. It ensures that customers' sensitive information is safe because it requires an extra step beyond just a password. Without this, a hacker who steals a password could easily access your customer data, leading to potential misuse or theft of information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.
policy ASD Information Security Manual (ISM) ISM-1892
priority_high

Why it matters

Without MFA for customer services, compromised passwords can allow account takeover and exfiltration of sensitive customer data, harming trust.

settings

Operational notes

Enforce MFA for all customer-service logins; manage enrolment, secure recovery, and monitor MFA bypass/failed challenges for fraud.

Mapping detail

Mapping

Direction

Controls