Glossary / frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

ASD Essential Eight controlsThe Australian Signals Directorate Essential Eight: application control, patch applications, Microsoft Office macros, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Maturity is 0 to 3 per control.01App control02Patch apps03Office macros04App hardening05Restrict admin06Patch OS07MFA08BackupsStrategyPriority focusESSENTIAL EIGHT / ASDMaturity 0 to 3. Pick a level you can hold, then hold it.Eight strategies. One maturity per control, not a blended score.

The Essential Eight is the Australian Signals Directorate's set of mitigation strategies that stop a large share of commodity intrusion. It is not a full information security program. It is the floor.

The eight: application control; patch applications; configure Microsoft Office macro settings; user application hardening; restrict administrative privileges; patch operating systems; multi-factor authentication; regular backups.

Maturity levels run from 0 (not aligned) to 3. Most organisations fail by claiming level 2 on paper and operating at 0 in the bits. Pick a level, evidence it, then move.

Use it with the ISM, not instead of it. Essential Eight is the short list; the ISM is the catalogue.