ISM-0421

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P

Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-0421

Debian 13 ISM Minimum Passphrase Length Component Definition 1.0.0 technically-tested unpublished

implemented Applicability claimed: NC, OS, P

pam_pwquality enforces a minimum passphrase length of 15 characters on non-classified, OFFICIAL: Sensitive and PROTECTED systems, via the drop-in 50-ism-minlen-nc-os-p.conf.

Verified by behaviour: the shortest passphrase the live policy accepts is measured, and nothing shorter than 15 characters is accepted. A 14-character candidate using every character class is also rejected, which shows credits are not lowering the minimum.

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)