Skip to content
arrow_back
search
ISM-2011 policy ASD Information Security Manual (ISM)

Restrict MFA Options to Phishing-resistant Only

Ensure accounts using strong, phishing-proof MFA can't use less secure authentication methods.

record_voice_over

Plain language

This control is about making sure your online accounts are really hard to hack even if someone tricks you into giving away information via phishing scams. It matters because phishing-proof multi-factor authentication (MFA) helps keep your personal and business information safe by making it much harder for criminals to access your accounts, even if they get hold of your passwords.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.
policy ASD Information Security Manual (ISM) ISM-2011
priority_high

Why it matters

Failure to enforce phishing-resistant MFA can lead to account takeovers, exposing sensitive data and causing significant financial and reputational damage.

settings

Operational notes

Review user MFA enrolment and ensure only phishing-resistant methods remain enabled; disable SMS/OTP options and alert on any changes.

Mapping detail

Mapping

Direction

Controls