Skip to content
arrow_back
ISM-1561policyASD Information Security Manual (ISM)

Ensure Strong Passwords for TOP SECRET Systems

TOP SECRET systems must use passwords of at least 10 characters for added security.

record_voice_over

Plain language

Ensuring strong passwords on TOP SECRET systems is crucial because it makes it much harder for outsiders to guess or crack them. If someone guesses a password, they could access sensitive information and potentially cause serious harm to your organisation. This control requires that passwords in use for multi-factor authentication (where more than just a password is needed to log in) are at least 10 characters long, adding an important layer of security.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.
policyASD Information Security Manual (ISM)ISM-1561
priority_high

Why it matters

Weak passwords for TOP SECRET MFA could enable unauthorised access, exposing highly sensitive data and potentially jeopardising national security operations.

settings

Operational notes

Audit TOP SECRET MFA password length to ensure a 10+ character minimum; enforce policy and technical controls, and remediate any non-compliant accounts.

build

Implementation tips

  • The IT team should set up all accounts related to TOP SECRET systems to require passwords of at least 10 characters. They can do this by configuring the system settings to enforce this rule when new passwords are created or old ones are changed.
  • System owners need to ensure that their users understand the importance of strong passwords. They can organise short training sessions to demonstrate how to create passwords that are both long and easy to remember, using phrases or a mix of words and numbers.
  • Managers should regularly remind staff to avoid common passwords or words related to their personal life. They can send out monthly reminders through emails or meetings, giving examples of strong passwords and explaining the risks of weak ones.
  • The cyber security team should implement checks to automatically monitor and alert if any known weak passwords are used on the system. This can be done using security software that flags insecure passwords for further review.
  • Human Resources should include password best practices and the 10-character requirement in the employee onboarding process. New staff should sign a document acknowledging they understand and will follow these practices.
fact_check

Audit / evidence tips

  • AskThe system configuration settings: Request a screenshot or printout of the authentication settings that show the password requirementsGoodIt clearly states 'min. 10 characters' for systems handling TOP SECRET data
  • AskThe training schedule or material: Request documentation or a calendar showing when employees receive training about password securityGoodShows training was conducted before system access was provided and regularly updated
  • AskLogs or reports from the security software that flags weak passwordsGoodShows consistent monitoring activity and actions taken on any alerts
  • AskAn onboarding checklist: Request to see the document that HR uses to onboard new staffGoodNew employee files have signed checklists acknowledging password rules
  • AskCopies of recent emails or meeting notes that mention the password length requirementGoodShows consistent communication with acknowledgment from recipients
link

Cross-framework mappings

How ISM-1561 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.17ISM-1561 requires that passwords used as part of multi-factor authentication on TOP SECRET systems are at least 10 characters long

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls