Skip to content
arrow_back
search
ISM-1227 policy ASD Information Security Manual (ISM)

Randomly Generate User Account Credentials

User account passwords must be created randomly to enhance security.

record_voice_over

Plain language

Randomly generating passwords for user accounts makes it much harder for attackers to guess or crack them. If your passwords are predictable, cybercriminals can easily access your systems, potentially leading to data theft, financial loss, and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials set for user accounts are randomly generated.
policy ASD Information Security Manual (ISM) ISM-1227
priority_high

Why it matters

Without randomly generated user credentials, attackers can guess or crack predictable patterns, enabling account compromise and unauthorised access to sensitive data.

settings

Operational notes

Use an approved credential generator to create high-entropy initial passwords for all new accounts, block manual setting, and log/alert on any non-random credentials.

Mapping detail

Mapping

Direction

Controls