Skip to content
arrow_back
search
ISM-1560 policy ASD Information Security Manual (ISM)

Ensure Strong Passwords for SECRET System Authentication

Passwords for SECRET systems using multi-factor authentication must be at least 8 characters.

record_voice_over

Plain language

This control ensures that when logging into important systems, passwords used must be at least eight characters long, even if you're using a second method to verify your identity, like a text message code. This matters because strong passwords are a first line of defense against unauthorised access. If passwords are weak, cyber criminals can easily break into systems and steal sensitive information, causing operational downtime and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.
policy ASD Information Security Manual (ISM) ISM-1560
priority_high

Why it matters

If MFA passwords on SECRET systems are under 8 characters, they are easier to guess or crack, increasing account compromise and SECRET information exposure risk.

settings

Operational notes

Configure authentication to reject MFA passwords under 8 characters on SECRET systems, and routinely test/monitor for accounts that bypass the minimum length.

Mapping detail

Mapping

Direction

Controls