Skip to content
arrow_back
search
ISM-1561 policy ASD Information Security Manual (ISM)

Ensure Strong Passwords for TOP SECRET Systems

TOP SECRET systems must use passwords of at least 10 characters for added security.

record_voice_over

Plain language

Ensuring strong passwords on TOP SECRET systems is crucial because it makes it much harder for outsiders to guess or crack them. If someone guesses a password, they could access sensitive information and potentially cause serious harm to your organisation. This control requires that passwords in use for multi-factor authentication (where more than just a password is needed to log in) are at least 10 characters long, adding an important layer of security.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.
policy ASD Information Security Manual (ISM) ISM-1561
priority_high

Why it matters

Weak passwords for TOP SECRET MFA could enable unauthorised access, exposing highly sensitive data and potentially jeopardising national security operations.

settings

Operational notes

Audit TOP SECRET MFA password length to ensure a 10+ character minimum; enforce policy and technical controls, and remediate any non-compliant accounts.

Mapping detail

Mapping

Direction

Controls