Skip to content
arrow_back
boltEssential 8

Patch applications

13 controls in this part of theEssential Eight. Each control links to plain-English guidance, audit tips and cross-framework mappings.

E8-PA-ML1.1
Automated asset discovery at least fortnightly
E8-PA-ML1.2
Up-to-date vulnerability scanner used for scanning activities
E8-PA-ML1.3
Daily vulnerability scanning for missing patches in online services
E8-PA-ML1.4
Weekly scanning for missing patches or updates in key software
E8-PA-ML1.5
Apply critical application patches within 48 hours
E8-PA-ML1.6
Apply non-critical patches for online services within two weeks
E8-PA-ML1.8
Unsupported online services are removed by the organisation
E8-PA-ML1.9
Removal of unsupported software and applications
E8-PA-ML2.1
Fortnightly vulnerability scanning for non-core applications
E8-PA-ML2.2
Timely Patching of Non-Critical Application Vulnerabilities
E8-PA-ML3.1
Patch critical vulnerabilities in applications within 48 hours
E8-PA-ML3.2
Apply patches for non-critical vulnerabilities within two weeks
E8-PA-ML3.3
Remove unsupported applications excluding certain categories

Back to the full ASD Essential Eight control list, or browse the complete control library.