ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.AUTH.MFA: Multi-factor authentication for all staff and end users (DSP-controlled products)

Mandatory for categories A to C: multi-factor authentication is implemented for all staff and end users who access tax, accounting, payroll, business registry or superannuation information for themselves or for other entities or individuals (including tax agents and employers), consistent with the Australian Government guidelines for system hardening. MFA is permanent and cannot be disabled by the client; all cloud environments holding in-scope data require MFA; all DSP staff with privileged access use MFA; authenticator apps may be used if enforcement at login is demonstrated; social media logins are not to be used as MFA (a model relying on them is discussed with the Digital Partnership Office); any variation from full MFA is discussed with the OSF team, who may accept compensating controls. SMS is recognised as weaker and an alternative factor is recommended where appropriate. Recommended as best practice for categories D and E.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-1173 Multi-factor authentication for privileged users
  • ISM-1892 MFA for own sensitive customer services
  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1

ISO 27002:2022 · 1 control

  • 8.5 Secure authentication

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.