The Essential Eight.
Australia's baseline cyber security mitigation strategies. 8 strategies, 3 maturity levels, 149 controls.
What is the ASD Essential Eight?
The ASD Essential Eight is a set of eight baseline cyber security mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). It is the practical starting point most Australian organisations use to reduce the risk of the cyber threats they are most likely to face.
Rather than a full risk-management standard, the ASD Essential Eight prescribes eight concrete technical controls, measured across three maturity levels. The eight strategies span preventing malicious code from running, keeping software patched, limiting administrative access, and being able to recover from an incident. Australian Government entities are mandated to implement them, and industry increasingly treats the Essential Eight as a minimum baseline.
The 8 strategies.
Each targets a specific attack vector or reduces the impact of a security incident. Open any strategy for its full control list.
Application Control
Prevent unapproved and malicious applications from executing. Only allow trusted, approved software to run.
Patch Applications
Apply security patches to applications within defined timeframes, focusing on internet-facing and untrusted content apps.
Configure Office Macro Settings
Block macros from the internet and only allow vetted, trusted macros to execute.
User Application Hardening
Block ads, Java, Flash, and unnecessary features that attackers exploit in web browsers and productivity apps.
Restrict Administrative Privileges
Limit admin access to those who need it. Use separate accounts for administrative tasks.
Patch Operating Systems
Apply OS patches within defined timeframes. Replace end-of-life systems with supported versions.
Multi-Factor Authentication
Require MFA for VPNs, remote access, privileged actions, and all internet-facing services.
Regular Backups
Perform and test backups of important data. Store backups offline or where compromised accounts cannot reach them.
Three maturity levels.
Each of the eight strategies is assessed against three maturity levels. Your organisation's overall maturity is the lowest level achieved across all eight strategies, so a single weak strategy caps the whole rating.
Maturity Level 1
Protects against commodity, opportunistic attacks that use widely available tradecraft.
In practice: Patch internet-facing services within two weeks, enforce MFA for internet-facing services, and take daily backups.
Maturity Level 2
Protects against adversaries willing to invest more time and use better tools to bypass basic controls.
In practice: Faster patching, phishing-resistant MFA for privileged users, centralised event logging and macro execution restrictions.
Maturity Level 3
Protects against adaptive, well-resourced adversaries including nation-state actors.
In practice: Application control on all workstations and servers, just-in-time administration, and tested offline backups.
Essential 8 Maturity Model
Three maturity levels from ML1 (basic, commodity threats) to ML3 (sophisticated adversaries including nation-state actors). Your overall maturity equals the lowest level across all 8 strategies.
View maturity modelarrow_forwardISO 27001 to Essential Eight mapping
Already certified to ISO/IEC 27001? See exactly which ISO 27001 Annex A controls map to each Essential Eight strategy in our free crosswalk tool.
Open the mapping toolarrow_forwardWho must comply?
- Australian Government agencies - Mandatory under the PSPF since July 2022. Agencies must report maturity levels to the ACSC.
- Defence industry - The DISP references Essential 8 maturity as part of security requirements for contractors and suppliers.
- Critical infrastructure operators - Encouraged under the SOCI Act 2018 to adopt ASD mitigation strategies.
- Private sector - Voluntary, but increasingly expected in government tenders, supply chain agreements, and cyber insurance.
- State and territory agencies - Many have adopted the Essential 8 as their baseline cyber security framework.
E8 vs ISO 27001 vs ASD ISM.
| Essential 8 | ISO 27001 | ASD ISM | |
|---|---|---|---|
| Controls | 149 | 93 | 1,073 |
| Focus | 8 priority mitigations | Full ISMS | Comprehensive technical guidelines |
| Mandatory for | AU Government | Voluntary (contractual) | AU Government |
| Best for | Baseline hygiene | Certification | Detailed technical |
| Maturity model | Yes (ML1-ML3) | No (pass/fail) | No |
Control Stack maps controls across these frameworks plus ISO 42001 for AI governance.
Start checking your compliance.
Use Control Stack to review your Essential 8 posture at every maturity level, with plain-English guidance and cross-framework mappings.
The Essential 8 aligns with ISO 27001 controls. Mindset Cyber offers PECB-accreditedISO 27001 training.