Skip to content
arrow_back
shieldASD Framework

The Essential Eight.

Australia's baseline cyber security mitigation strategies. 8 strategies, 3 maturity levels, 149 controls.

What is the ASD Essential Eight?

The ASD Essential Eight is a set of eight baseline cyber security mitigation strategies published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). It is the practical starting point most Australian organisations use to reduce the risk of the cyber threats they are most likely to face.

Rather than a full risk-management standard, the ASD Essential Eight prescribes eight concrete technical controls, measured across three maturity levels. The eight strategies span preventing malicious code from running, keeping software patched, limiting administrative access, and being able to recover from an incident. Australian Government entities are mandated to implement them, and industry increasingly treats the Essential Eight as a minimum baseline.

The 8 strategies.

Each targets a specific attack vector or reduces the impact of a security incident. Open any strategy for its full control list.

Three maturity levels.

Each of the eight strategies is assessed against three maturity levels. Your organisation's overall maturity is the lowest level achieved across all eight strategies, so a single weak strategy caps the whole rating.

Maturity Level 1

Protects against commodity, opportunistic attacks that use widely available tradecraft.

In practice: Patch internet-facing services within two weeks, enforce MFA for internet-facing services, and take daily backups.

Maturity Level 2

Protects against adversaries willing to invest more time and use better tools to bypass basic controls.

In practice: Faster patching, phishing-resistant MFA for privileged users, centralised event logging and macro execution restrictions.

Maturity Level 3

Protects against adaptive, well-resourced adversaries including nation-state actors.

In practice: Application control on all workstations and servers, just-in-time administration, and tested offline backups.

trending_up

Essential 8 Maturity Model

Three maturity levels from ML1 (basic, commodity threats) to ML3 (sophisticated adversaries including nation-state actors). Your overall maturity equals the lowest level across all 8 strategies.

View maturity modelarrow_forward
swap_horiz

ISO 27001 to Essential Eight mapping

Already certified to ISO/IEC 27001? See exactly which ISO 27001 Annex A controls map to each Essential Eight strategy in our free crosswalk tool.

Open the mapping toolarrow_forward
Who must comply?
  • Australian Government agencies - Mandatory under the PSPF since July 2022. Agencies must report maturity levels to the ACSC.
  • Defence industry - The DISP references Essential 8 maturity as part of security requirements for contractors and suppliers.
  • Critical infrastructure operators - Encouraged under the SOCI Act 2018 to adopt ASD mitigation strategies.
  • Private sector - Voluntary, but increasingly expected in government tenders, supply chain agreements, and cyber insurance.
  • State and territory agencies - Many have adopted the Essential 8 as their baseline cyber security framework.

E8 vs ISO 27001 vs ASD ISM.

Essential 8ISO 27001ASD ISM
Controls149931,073
Focus8 priority mitigationsFull ISMSComprehensive technical guidelines
Mandatory forAU GovernmentVoluntary (contractual)AU Government
Best forBaseline hygieneCertificationDetailed technical
Maturity modelYes (ML1-ML3)No (pass/fail)No

Control Stack maps controls across these frameworks plus ISO 42001 for AI governance.

Start checking your compliance.

Use Control Stack to review your Essential 8 posture at every maturity level, with plain-English guidance and cross-framework mappings.

The Essential 8 aligns with ISO 27001 controls. Mindset Cyber offers PECB-accreditedISO 27001 training.