ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.AUTH.UNIQUE: Unique user logins, shared logins blocked

All solutions have user-based access with unique client logins and authentication and authorisation controls (for example a unique username and password); shared logins are not permitted and must be blocked by the DSP, so each user and session is uniquely identifiable in audit logs. This is the minimum authentication requirement for categories D and E and part of the MFA requirement for A to C. Where MFA is not implemented, the DSP should consider passphrase management, account lockout and passphrase reset practices from the Australian Government guidelines for system hardening.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-0415 Controlling shared user accounts

ISO 27002:2022 · 1 control

  • 5.16 Identity management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.