ISM-2078

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P, S, TS

Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-2078

Debian 13 ISM Dictionary Checking Component Definition 1.0.0 technically-tested unpublished

partial Applicability claimed: NC, OS, P, S, TS

Partially implemented. dictcheck = 1 evaluates every candidate against the cracklib dictionary, and badwords rejects organisation-specific terms.

Measured on a clean Debian 13 install, with candidates padded to at or above the minimum length in force so that length cannot be the reason for rejection: 1 of 8 common breach-list passwords was rejected at a 15-character minimum, and 2 of 8 at 20. The stock cracklib dictionary is a common-word corpus, not a breach-credential corpus, so the substantive requirement is not met by this configuration alone.

Residual risk Measured: only 1 of 8 long common passwords rejected at minlen 15. cracklib is not a breach-credential corpus.

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)