ISM-2080

Password strength

Australian Cyber Security Centre · Information Security Manual v2026.09.4 · Applicability NC, OS, P, S, TS

Password complexity requirements are not imposed for passwords.

Guidelines for system access › Credential management › Password strength

Components addressing ISM-2080

Debian 13 ISM No Complexity Requirement Component Definition 1.0.0 technically-tested unpublished

implemented Applicability claimed: NC, OS, P, S, TS

Implemented. dcredit, ucredit, lcredit and ocredit are all 0, so no character class earns credit and none is required; minclass = 0 imposes no class-count floor.

Verified by behaviour: an all-lowercase passphrase at the minimum length in force is accepted, which shows length alone governs.

Configuration and scripts

This control's implementations as an OSCAL component definition (newest version of each component)