Skip to content
arrow_back
search
ISM-1557 policy ASD Information Security Manual (ISM)

Ensure Strong Passwords for SECRET Systems

Passwords for SECRET systems must be at least 17 characters long to enhance security.

record_voice_over

Plain language

This control means that any time you're logging into a system classified as SECRET, your password needs to be at least 17 characters long. This is important because longer passwords help protect sensitive information from being accessed by unauthorised people, reducing the risk of data breaches or leaks that could have serious consequences for your organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.
policy ASD Information Security Manual (ISM) ISM-1557
priority_high

Why it matters

Inadequate password length on SECRET systems increases susceptibility to brute-force guessing, enabling unauthorised access to SECRET data and broader compromise of classified operations.

settings

Operational notes

Enforce a minimum 17-character password policy for all single-factor SECRET system accounts; use password managers to generate unique passwords and verify compliance via periodic audits.

Mapping detail

Mapping

Direction

Controls