ISM-1557

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability S

Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-1557

Debian 13 ISM Minimum Passphrase Length Component Definition 1.0.0 technically-tested unpublished

implemented Applicability claimed: S

pam_pwquality enforces a minimum passphrase length of 17 characters on SECRET systems, via the drop-in 50-ism-minlen-s.conf.

Verified by behaviour on a SECRET-tier system: nothing shorter than 17 characters is accepted.

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)