Skip to content
arrow_back
search
ISM-1893 policy ASD Information Security Manual (ISM)

Enforcing Multi-Factor Authentication for User Security

Users must use multi-factor authentication to access third-party services handling sensitive data.

record_voice_over

Plain language

This control means you need to add an extra layer of security when accessing online services that handle important customer data. This matters because if someone tries to hack into these systems, multi-factor authentication makes it much harder for them to succeed, protecting your sensitive information from theft or misuse.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.
policy ASD Information Security Manual (ISM) ISM-1893
priority_high

Why it matters

Without MFA on third-party customer services, attackers can take over accounts and access or exfiltrate sensitive customer data, causing a breach.

settings

Operational notes

Enforce MFA on all third-party customer services handling sensitive customer data; review MFA settings and logs after changes and user onboarding.

Mapping detail

Mapping

Direction

Controls