Skip to content
arrow_back
search
ISM-1685 policy ASD Information Security Manual (ISM)

Strengthening Passwords for Critical Accounts

Ensure passwords for high-risk accounts are strong, unique, and properly managed.

record_voice_over

Plain language

This control is about ensuring that important accounts, which have powerful access to your systems, have strong, unique passwords that are kept safe. It's important because if these accounts are compromised, your entire organisation could be at risk of data theft, financial loss, or operational downtime.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
policy ASD Information Security Manual (ISM) ISM-1685
priority_high

Why it matters

Weak or reused passwords for break glass, local admin and service accounts enable easy compromise, leading to unauthorised privileged access, breaches and major financial/reputational damage.

settings

Operational notes

For break glass, local admin and service accounts, enforce long unique passwords, store in an approved vault, rotate routinely and on staff changes, and restrict/monitor access.

Mapping detail

Mapping

Direction

Controls