Skip to content
arrow_back
search
ISM-1980 policy ASD Information Security Manual (ISM)

Avoid Using Credential Hints in Systems

Systems should not use hints to reveal or guess passwords.

record_voice_over

Plain language

You should avoid using hints that help people remember passwords because they can make it easier for bad actors to guess them. If someone figures out your password, they could access your organisation's sensitive information and cause harm, such as stealing data or disrupting operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credential hint functionality is not used for systems.
policy ASD Information Security Manual (ISM) ISM-1980
priority_high

Why it matters

Credential hints increase the likelihood of unauthorised access by simplifying password guessing, risking data breaches and financial loss.

settings

Operational notes

Regularly review authentication systems to ensure they're free from hint mechanisms that could aid attackers in guessing credentials.

Mapping detail

Mapping

Direction

Controls