Skip to content
arrow_back
search
ISM-2076 policy ASD Information Security Manual (ISM)

Eliminating Security Questions for Authentication

Authentication should not use security questions as they can be easily compromised.

record_voice_over

Plain language

This control is about stopping the use of security questions to verify someone's identity. These questions, like 'What is your mother's maiden name?', can be easily guessed or found out by others, putting your data at risk. If you keep using them, someone could pretend to be you and access sensitive information or take harmful actions without your knowledge.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security questions are not used for authentication purposes.
policy ASD Information Security Manual (ISM) ISM-2076
priority_high

Why it matters

If security questions remain, attackers can guess or obtain answers and reset accounts, causing unauthorised access and data breaches.

settings

Operational notes

Audit authentication and account recovery flows to ensure security questions are removed and no fallback prompts appear in apps or helpdesk scripts.

Mapping detail

Mapping

Direction

Controls