Essential Eight
Assessment and alignment
The Australian Signals Directorate publishes eight mitigation strategies and three target maturity levels. We assess every control against them, tell you where you actually sit, and give you the shortest path to the level you need. Sold on its own, before anything is bought or changed.
The eight strategies
Published by the Australian Signals Directorate, mandatory for federal non-corporate entities, adopted widely across state agencies, and increasingly the thing insurers and enterprise procurement teams ask about by name.
-
Application control
Only approved software runs. Stops most commodity malware before any detection has to work.
-
Patch applications
Known holes closed inside defined windows, with the riskiest closed fastest.
-
Configure Microsoft Office macro settings
Macros blocked except where a business case exists, because a document is still one of the easiest ways in.
-
User application hardening
Browsers and common applications stripped of the features attackers use and users do not.
-
Restrict administrative privileges
Fewer people hold admin, for less time. This control limits how far an intruder can travel once inside; it does not stop them getting in.
-
Patch operating systems
The same discipline as applications, applied to the platform underneath them.
-
Multi-factor authentication
A stolen password stops being enough on its own. The highest return control on the list.
-
Regular backups
Tested, and out of reach of whoever encrypted the originals. Often the difference between a bad week and a closure.
Maturity Level 0 describes the baseline, with three target maturity levels above it. What they measure is how completely each strategy is implemented, not how many of the eight you have. An organisation sits at the level of its weakest strategy, which is why an assessment reports all eight separately and why a single headline percentage is never the whole answer.
Someone is going to ask you to prove it
Your insurer asks at renewal. Your board asks after somebody else's incident makes the news. Your largest customer's procurement team asks before they sign, and increasingly they name the Essential Eight when they do.
The answer most organisations can give is a list of the tools they own. That is not a position. It cannot be compared year on year, it cannot be handed to an auditor, and it is the answer that turns a renewal into a problem.
Published guidance fixes that. Measured against the Essential Eight, a set of opinions becomes a maturity level that means the same thing to you, your auditor and your insurer.
What an assessment gives you
One engagement, three outputs. It runs before anything is bought or changed, because everything afterwards is measured against it.
-
A control-level position
149 controls across the eight strategies, each recorded as implemented, partial or not in place, against the maturity level you actually need. Not a tooling inventory. A position, control by control.
-
An executive report
One score, the maturity level currently held, the strategies holding it back, and a maturity heat map. Written to be handed to a board or an insurer without translation.
-
A prioritised roadmap
The outstanding gaps ranked by risk, with the shortest path to the next level, which is seldom a list of everything at once. It frequently shows less work than expected.
What an assessment is, and what it is not
A measurement against published guidance. Being precise about what that does and does not amount to is the whole value of it.
What it does
-
A defensible position
Scored control by control against the wording of the ASD guidance, so the number is reproducible and the method is inspectable.
-
Comparable over time
Reassess and the trend is the output. A single assessment is a snapshot; the value is in the second one.
-
Independent of what you buy next
The assessment does not assume you will buy anything. Sometimes it says the tier below the one you were considering is enough for now.
-
Written for two audiences
A technical gap list for whoever does the work, and an executive summary for whoever signs it off.
What it does not do
-
Not a certification
There is no Essential Eight certificate. It is ASD guidance, so no body accredits or certifies anyone against it. Any provider offering to make you "ML2 certified" is describing something that does not exist.
-
Not an audit
This is an assessment against published guidance. It is neither a statutory audit nor an IRAP assessment, and where you need one of those it is a different engagement with a different assessor.
-
Not remediation
The assessment identifies and prioritises. Fixing is separate work, whether we do it or you do.
-
Not a penetration test
It measures whether controls are implemented. A penetration test measures whether someone can get past them, and neither substitutes for the other.
-
Not a guarantee
A high maturity level reduces how many ways in exist and how far an intruder travels. It does not make an organisation unbreachable, and it should not be sold as though it did.
What usually happens next
Three outcomes, and the assessment settles which one applies.
-
Align the whole environment
If the gaps are spread across all eight strategies, individual controls will not close them and coordinating it yourself is a job. The uplift can be scoped as a project of its own, whoever runs your IT afterwards. Alignment drifts unless the controls continue to be operated, so where you want it maintained, Managed IT Fortify aligns all eight strategies to the ASD guidance at Maturity Level 2 as part of ongoing delivery, and scores them.
-
Close one or two named gaps
If the assessment finds the weakness concentrated, and it usually is, in application control, endpoint detection, email or user awareness, then one or two modular controls close it without moving your IT. That is the cheaper answer and it is often the right one. Where the gap is in patching, administrative privileges or macro settings, it is tenant configuration and the work sits with whoever runs your tenant; where that is Ericom, it is Managed IT.
-
Do nothing yet
Sometimes the position is better than expected and the honest recommendation is to reassess in twelve months. We would rather tell you that than sell against it.
“Some job seekers send CVs through to our emails instead of our secured portal, and we’ve always needed to work around that. Now, our staff are educated on best practices, which has improved our overall security measures.”
Senior Business Manager, Bluefin Resources
Common questions
Short answers first.
What is the Essential Eight?
Eight mitigation strategies published by the Australian Signals Directorate, chosen because together they make the attacks most commonly attempted against Australian organisations much harder to carry out. They are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.
It is deliberately short. The argument is not that eight controls are sufficient for everything, but that these eight address most of what is actually being attempted, and that most organisations have not fully implemented them. You will see it written as Essential 8 as often as Essential Eight; the two are the same guidance.
What are the Essential Eight maturity levels?
Maturity Level 0 describes the baseline, with three target maturity levels above it. Each of the three says how completely a strategy is implemented, from a partial deployment to one that meets the wording of the guidance.
Maturity Level 1 addresses opportunistic attackers using widely available tools. Level 2 addresses attackers willing to invest more time and to work a little harder at getting around controls. Level 3 addresses adaptive attackers who will target a specific organisation and adjust to what they find.
You sit at the level of your weakest strategy, not your average, which is why a high overall percentage and a low maturity level routinely appear in the same report.
Can you be certified against the Essential Eight?
No, and it matters that the answer is no. The Essential Eight is ASD guidance, so there is no accreditation body, no certificate and no attestation. What can be done is assess against the wording, align every control to it at the level you need, and report the position, which is what an insurer or a procurement team is asking for.
Is the Essential Eight mandatory?
For Australian federal non-corporate entities, yes. They are directed to implement it and to report against it. For everyone else it is not law, but it is increasingly contractual: state agencies apply it, insurers ask about it at renewal, and enterprise procurement teams ask suppliers to evidence it. In practice most organisations meet it as a condition of doing business before it is ever a matter of regulation.
Which maturity level do we need?
ASD frames the levels by the tradecraft of the attacker each is meant to withstand; size and sector do not enter into it. In practice most Australian mid-market organisations are working toward Level 2, which is also the level Managed IT Fortify aligns to. Level 3 is a significant step and is usually driven by a specific obligation. The assessment is what settles it, because it also tells you what the next level would actually cost you.
How long does an assessment take, and what do we have to do?
A facilitated review with the people who know your environment, plus read access to the systems that hold the evidence. Most of the work is ours. You get the report and the roadmap, and there is no obligation to buy anything afterwards.
Is this the same as an IRAP assessment?
No. IRAP is a separate ASD programme, carried out by registered assessors, generally where systems handle Australian government information. An Essential Eight assessment measures implementation of the eight strategies and is not a substitute for it. If IRAP is what you have been asked for, say so early. It is a different engagement with a different assessor.
How an assessment runs
Three steps, and a report you own at the end of them regardless of what you decide to do next.
-
Scope the target level
Which maturity level you are being measured against, and by whom. Assessing against a level that neither your insurer nor your customer has asked for wastes the exercise.
-
Assess every control
All eight strategies, control by control, against the wording of the ASD guidance. Implemented, partial, or not in place.
-
Report and prioritise
The executive report, the heat map and the roadmap. Then a conversation about the shortest path, which sometimes concludes that you should wait.
A level you can defend
A level is defensible when it was scored against the wording of the guidance, so that somebody else could reproduce the number; when the second assessment can be set beside the first and the difference explained; and when the controls behind it are still where the assessment found them at the next renewal. An assessment produces the first two. The third is the work that follows it, whoever does it.
Find out what level you are at
Who is asking, and which level have they named? An assessment gives you a score, a maturity level and a prioritised list. It also tells you whether you need less than you think, which is a perfectly good outcome and happens more often than you would expect.
Book an Essential Eight assessment