Mandatory for categories A to C: multi-factor authentication is implemented for all staff and end users who access tax, accounting, payroll, business registry or superannuation information for themselves or for other entities or individuals (including tax agents and employers), consistent with the Australian Government guidelines for system hardening. MFA is permanent and cannot be disabled by the client; all cloud environments holding in-scope data require MFA; all DSP staff with privileged access use MFA; authenticator apps may be used if enforcement at login is demonstrated; social media logins are not to be used as MFA (a model relying on them is discussed with the Digital Partnership Office); any variation from full MFA is discussed with the OSF team, who may accept compensating controls. SMS is recognised as weaker and an alternative factor is recommended where appropriate. Recommended as best practice for categories D and E.
This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.