Skip to content
arrow_back
search
ISM-0422 policy ASD Information Security Manual (ISM)

Ensuring Strong Passwords for TOP SECRET Systems

Passwords on TOP SECRET systems should be at least 20 characters to ensure strong security.

record_voice_over

Plain language

This control means that passwords for systems holding highly sensitive information need to be at least 20 characters long. It’s important because a weak password could let someone unauthorized into your system, potentially leading to stolen information, financial losses, or harm to your reputation if sensitive data leaks.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 characters.
policy ASD Information Security Manual (ISM) ISM-0422
priority_high

Why it matters

Weak single-factor passwords on TOP SECRET systems increase the likelihood of credential guessing and unauthorised access, risking compromise of highly classified information and national security.

settings

Operational notes

Enforce a minimum 20-character password policy for TOP SECRET single-factor accounts; regularly audit compliance, prevent reuse, and alert on repeated failed logons indicating password guessing.

Mapping detail

Mapping

Direction

Controls