Skip to content
arrow_back
search
ISM-1894 policy ASD Information Security Manual (ISM)

Ensuring Phishing-Resistant Multi-factor Authentication

Ensure multi-factor authentication resists phishing attempts for secure data access.

record_voice_over

Plain language

Phishing-resistant multi-factor authentication is like having a double lock on your door that can't be tricked open with a fake key. This matters because cyber criminals might try to steal your login credentials to access sensitive information, but with this kind of security, simply having your password isn't enough for them to break in.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
policy ASD Information Security Manual (ISM) ISM-1894
priority_high

Why it matters

Without phishing-resistant MFA (e.g., FIDO2/WebAuthn), attackers can relay credentials via phishing, leading to repository compromise and data breach.

settings

Operational notes

Regularly confirm only phishing-resistant MFA (FIDO2/WebAuthn) is permitted for repository access, and monitor logs/alerts for any unauthorised MFA policy changes.

Mapping detail

Mapping

Direction

Controls