Skip to content
arrow_back
search
ISM-2080 policy ASD Information Security Manual (ISM)

No Password Complexity Requirements Enforced

Passwords do not need to follow strict complexity rules.

record_voice_over

Plain language

This control means that when people are creating passwords, they don't have to make them complicated with a mix of letters, numbers, and symbols. If passwords are not strong enough, it becomes easier for hackers to guess them and gain access to confidential information, putting the whole organisation at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Password complexity requirements are not imposed for passwords.
policy ASD Information Security Manual (ISM) ISM-2080
priority_high

Why it matters

Without password complexity requirements, users may choose weak passwords, making brute-force and credential guessing easier and increasing unauthorised access risk.

settings

Operational notes

Monitor for compromised credentials, enforce MFA, and use password screening against breached-password lists to reduce the impact of weak, user-chosen passwords.

Mapping detail

Mapping

Direction

Controls