Chapter 10 Install and System Administration for FortiOS 5.0 : Basic Administration : Passwords : Password considerations
  
Password considerations
When changing the password, consider the following to ensure better security.
Do not make passwords that are obvious, such as the company name, administrator names, or other obvious word or phrase.
Use numbers in place of letters, for example, passw0rd. Alternatively, spell words with extra letters, for example, password.
Administrative passwords can be up to 64 characters.
Include a mixture of letters, numbers, and upper and lower case.
Use multiple words together, or possibly even a sentence, for example keytothehighway.
Use a password generator.
Change the password regularly and always make the new password unique and not a variation of the existing password, such as changing from password to password1.
Write the password down and store it in a safe place away from the management computer, in case you forget it or ensure that at least two people know the password in the event that one person becomes ill, is away on vacation or leaves the company. Alternatively, have two different admin logins.
See Also
Passwords
Password policy
Forgotten password?