Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.
ISM-1557
Password strength
Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability S
Components addressing ISM-1557
implemented Applicability claimed: S
pam_pwquality enforces a minimum passphrase length of 17 characters on SECRET systems, via the drop-in 50-ism-minlen-s.conf.
Verified by behaviour on a SECRET-tier system: nothing shorter than 17 characters is accepted.
Configuration and scripts
- config/pwquality.conf.d/50-ism-minlen-s.conf Minimum length, applicability S
sha256 af3bf12f39953df4e9fcf93c1914bac88d002ff5f16153ab49549fe1baf6fd2c - scripts/verify-minlen.sh Verification script
sha256 010aa56c327cc1e28d05a0acf4ba8c47f6fdfdb2784b301a33edad87f1497fd8
This control's implementations as an OSCAL component definition (newest version of each component)