Skip to content
arrow_back
search
ISM-2047 policy ASD Information Security Manual (ISM)

Notify Users of Authentication Resets via Secondary Channel

When a software authentication factor is reset, users are informed through an additional communication method.

record_voice_over

Plain language

When you're allowed to reset a password or other security check, this control makes sure you're informed through a different method, like an email or text. This matters because if someone else tries to mess with your account, you'll know about it right away and can act quickly to protect your information.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.
policy ASD Information Security Manual (ISM) ISM-2047
priority_high

Why it matters

Without secondary-channel notification, users may not detect unauthorised factor resets, enabling attackers to take over accounts unnoticed.

settings

Operational notes

Send reset alerts via a separate channel (e.g., SMS, email, push) immediately on factor reset, using automation and logging to verify delivery.

Mapping detail

Mapping

Direction

Controls