Australia
Essential Eight Maturity Level One and cyber insurance
At Maturity Level One, only the requirements ASD sets at level one count as gaps; level two requirements read "above your target level". Moving the target to Maturity Level Two turns them into gaps on the same schedule.
The controls
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
- Administrator accounts (other than the backup administrator) cannot change or delete backups
- Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
- Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
- Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
- Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.