Glossary / practitioner au-compliance frameworks hardening

PSPF Policy 14 — Cyber Security Strategies

PSPF Release 2025 Policy 14 is the Commonwealth cyber floor: Essential Eight to Maturity Level 2 for NCEs since 1 July 2022, plus risk-based use of the wider ASD mitigation catalogue. Overall maturity equals the weakest strategy.

Under PSPF Release 2025, Policy 14: Cyber Security Strategies is where non-corporate Commonwealth entities (NCEs) get their cyber floor. It carries forward the Essential Eight mandate that previously sat under the Policy 10 information-security line. Policy 14 is Attorney-General's Department protective-security policy, not an ASD technical standard by itself — the work still runs through ASD's Essential Eight Maturity Model and the ISM.

Since 1 July 2022, Policy 14 requires NCEs to implement all eight Essential Eight strategies to at least Maturity Level 2, and to consider whether their threat environment warrants Level 3. ASD's Commonwealth cyber security posture reports (2024 and 2025) restate that duty. The eight: application control; patch applications; configure Microsoft Office macro settings; user application hardening; restrict administrative privileges; patch operating systems; multi-factor authentication; and regular backups.

Maturity is not an average. ASD and the posture reporting are explicit: a network's overall maturity equals its least mature strategy. If MFA looks polished and application control is at 0, you are at 0. Plan and evidence the package together. Policy 14 also expects entities to consider which of the remaining Strategies to Mitigate Cyber Security Incidents (beyond the Essential Eight) are required for their threat picture — that is a risk decision with an owner, not a checkbox.

Evidence and reporting sit with the PSPF Release 2025 list of requirements (AGD spreadsheet) and ASD's annual Commonwealth cyber security posture survey. Map each strategy to scope, configuration artefact, last-checked date, and owner. Exceptions expire in writing. Corporate Commonwealth entities and industry suppliers are not automatically NCEs, but Policy 14 language is the dialect boards and contracts use when they say 'Essential Eight ML2'.

Use this page with the PSPF overview, Essential Eight evidence, and IRAP pages. For the control catalogue underneath the floor, use the ISM. For the annual survey and posture numbers, use ASD's Commonwealth cyber security posture publications on cyber.gov.au.

See also:

Fact source: ASD's ACSC — The Commonwealth Cyber Security Posture in 2025 (Policy 14 / Essential Eight ML2).