Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.
ISM-0421
Password strength
Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P
Components addressing ISM-0421
implemented Applicability claimed: NC, OS, P
pam_pwquality enforces a minimum passphrase length of 15 characters on non-classified, OFFICIAL: Sensitive and PROTECTED systems, via the drop-in 50-ism-minlen-nc-os-p.conf.
Verified by behaviour: the shortest passphrase the live policy accepts is measured, and nothing shorter than 15 characters is accepted. A 14-character candidate using every character class is also rejected, which shows credits are not lowering the minimum.
Configuration and scripts
- config/pwquality.conf.d/50-ism-minlen-nc-os-p.conf Minimum length, applicability NC, OS, P
sha256 3df2c1183d63fdcd66bc739d410cebfa8929bfc926bc3a21d908478dd9d76bf8 - scripts/verify-minlen.sh Verification script
sha256 010aa56c327cc1e28d05a0acf4ba8c47f6fdfdb2784b301a33edad87f1497fd8
This control's implementations as an OSCAL component definition (newest version of each component)