Skip to content
arrow_back
search
ISM-1795 policy ASD Information Security Manual (ISM)

Set 30-Character Minimum for Key Administrator Passwords

Ensure key system accounts use passwords that are at least 30 characters long to enhance security.

record_voice_over

Plain language

This control is about making sure important system accounts have strong passwords that are at least 30 characters long. It's crucial because weak passwords can be easily guessed or cracked by attackers, which might allow them to access and control your systems, leading to data breaches or operational disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.
policy ASD Information Security Manual (ISM) ISM-1795
priority_high

Why it matters

If Administrator, break-glass, local admin or service account passwords are under 30 characters, attackers can brute-force or spray credentials and gain full administrative control.

settings

Operational notes

Enforce a 30+ character minimum for built-in Administrator, break-glass, local admin and service accounts; routinely audit and rotate them using a password manager.

Mapping detail

Mapping

Direction

Controls