Australia
Essential 8 gap analysis for cyber insurance
Mark each control in place, partly, not in place or not sure, pick the target maturity level, and the gaps come back with the ISM-numbered Essential Eight requirement behind each one, split by the maturity level ASD sets, and a 90-day schedule for closing them.
The controls
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
- Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
- Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
- Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
- Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.