Skip to content
arrow_back
search
ISM-1559 policy ASD Information Security Manual (ISM)

Minimum Password Length for Secure Systems

Passwords for secure systems should have at least 6 characters to enhance security.

record_voice_over

Plain language

Having a password with at least 6 characters for systems that require additional security helps keep everything safe and private. If passwords are too short, they're easier for attackers to guess, which could lead to unauthorised access, putting sensitive information and overall business operations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
policy ASD Information Security Manual (ISM) ISM-1559
priority_high

Why it matters

If MFA passwords are shorter than 6 characters, brute-force guessing becomes easier, increasing the risk of unauthorised access to OFFICIAL: Sensitive/PROTECTED systems and potential data compromise.

settings

Operational notes

Configure MFA to enforce a minimum 6-character password on OFFICIAL: Sensitive and PROTECTED systems; verify via regular configuration checks and authentication policy audits to ensure the setting remains enforced.

Mapping detail

Mapping

Direction

Controls