Skip to content
arrow_back
search
ISM-0421 policy ASD Information Security Manual (ISM)

Require Minimum 15-Character Passwords for Security

Passwords for sensitive systems must have at least 15 characters to enhance security.

record_voice_over

Plain language

This control requires that all passwords used to access sensitive systems must be at least 15 characters long. It's important because longer passwords are harder for attackers to guess or break, making it much harder for them to gain unauthorized access to your important systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.
policy ASD Information Security Manual (ISM) ISM-0421
priority_high

Why it matters

Using passwords under 15 characters makes brute-force and guessing attacks more feasible, increasing the likelihood of unauthorised access and compromise of OFFICIAL: Sensitive or PROTECTED data.

settings

Operational notes

Set systems to enforce a minimum 15-character password for single-factor logons, brief staff on creating long memorable passphrases, and promote password managers to reduce reuse and weak choices.

Mapping detail

Mapping

Direction

Controls