ACSC
The Australian Cyber Security Centre, part of ASD. Alerts, advice, assistance. cyber.gov.au and 1300 CYBER1.
11 entries
The Australian Cyber Security Centre, part of ASD. Alerts, advice, assistance. cyber.gov.au and 1300 CYBER1.
Known Exploited Vulnerabilities catalogue plus BOD 26-04 deadlines. If it is on KEV and you are internet-facing, treat exposure as an incident trigger, not a backlog item.
ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.
How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.
Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud against the ISM. The report is evidence. Authorisation stays with you.
A management system standard. The certificate is proof you run the system, not that you are unbreachable.
ASD's control catalogue for Australian government systems — and the shared dialect for anyone who needs to speak the same language. Applicability, tailoring, and dated exceptions are the work.
A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.
Identify, Protect, Detect, Respond, Recover — plus Govern in 2.0. A common language, not a certification.
AGD protective security policy for NCEs. Four domains, PSPF Release 2025 Policy 14 cyber floor, Essential Eight to Maturity Level 2 since July 2022.
Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.
Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary