ISM-2079

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P, S, TS

Maximum length limits for passwords are not less than 64 characters.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-2079

Debian 13 pam_pwquality Enforcement Base Component Definition 1.0.0 technically-tested unpublished

implemented Applicability claimed: NC, OS, P, S, TS

Implemented by omission. Neither pam_pwquality nor any drop-in in this family configures a maximum length, and pam_unix uses yescrypt, which does not truncate. The effective ceiling is the PAM response buffer, far above the 64-character floor this control requires.

Verified: a 72-character passphrase is accepted by pwscore(1).

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)