Home / Rules / Essential Eight Maturity Model / Essential Eight, Multi-factor authentication, ISM-1504 (Maturity Level One)
Essential Eight, Multi-factor authentication, ISM-1504 (Maturity Level One)
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1504 in ASD's Essential Eight to ISM mapping (December 2023).
Steps that cite it
- KC-02 S7 Which Essential Eight control failed?
Evidence commonly asked for
- Identity provider policy enforcing multi-factor authentication for the organisation's online services holding sensitive data
- List of those online services mapped to the policy
Accepted citation forms are listed on the answer format page.