ISM-0422

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability TS

Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 characters.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-0422

Debian 13 ISM Minimum Passphrase Length Component Definition 1.0.0 technically-tested unpublished

implemented Applicability claimed: TS

pam_pwquality enforces a minimum passphrase length of 20 characters on TOP SECRET systems, via the drop-in 50-ism-minlen-ts.conf.

Verified by behaviour on a TOP SECRET-tier system: nothing shorter than 20 characters is accepted.

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)