Skip to content
arrow_back
search
ISM-2079 policy ASD Information Security Manual (ISM)

Ensure Password Length is at Least 64 Characters

Passwords must allow a maximum length of at least 64 characters for increased security.

record_voice_over

Plain language

This control means that you should allow users to create passwords that are up to 64 characters long. It’s important because longer passwords can significantly increase security by making it harder for hackers to guess or crack them, protecting sensitive information and data from being stolen.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Maximum length limits for passwords are not less than 64 characters.
policy ASD Information Security Manual (ISM) ISM-2079
priority_high

Why it matters

If systems cap passwords below 64 characters, users must choose shorter secrets, reducing entropy and making brute-force and credential-stuffing attacks more likely to succeed.

settings

Operational notes

Confirm all authentication components (apps, IdPs, directories, gateways) allow at least 64-character passwords, and periodically test enforcement after upgrades or configuration changes.

Mapping detail

Mapping

Direction

Controls