# ISM password policy — commonly used and compromised passwords # # Source: ACSC ISM OSCAL catalogue v2026.09.4 # ism-2078 commonly used / compromised passwords are not used (all) # # dictcheck evaluates every candidate against the cracklib dictionary shipped by # cracklib-runtime. That is a common-word corpus, not a breach-credential corpus, # so this is a partial implementation; see the component README. # # Install to /etc/security/pwquality.conf.d/50-ism-dictionary.conf dictcheck = 1 # Organisation-specific terms that must never appear in a passphrase. Extend this # list with product names, project code names and site names. badwords = password passphrase debian trixie official protected secret