Cyber Insurance Subjectivity Tracker

Rules

Core list: Australia

ACSC Essential Eight

The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.

edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023). 126 requirements cited here. Every Essential Eight clause we hold.

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
ISM-1504
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1504 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Identity provider policy enforcing multi-factor authentication for the organisation's online services holding sensitive data; List of those online services mapped to the policy

ISM-1679
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1679 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Inventory of third-party online services processing sensitive data with multi-factor authentication status; Screenshots or configuration exports of multi-factor enforcement at each service

ISM-1680
Essential Eight, Maturity Level One

Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1680 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Inventory of third-party services holding non-sensitive data with multi-factor availability and status; Record of services where multi-factor authentication is not offered

ISM-1401
Essential Eight, Maturity Level One

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1401 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Authentication policy listing permitted factor combinations; Evidence that knowledge-only or two knowledge factors are not accepted

ISM-1505
Essential Eight

Multi-factor authentication is used to authenticate users of data repositories. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1505 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enforcing multi-factor authentication for users of data repositories (databases, file stores, document systems); Repository list mapped to authentication method

Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
ISM-1681
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1681 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Customer authentication flow showing a second factor for services holding sensitive customer data; Customer enrolment statistics

ISM-1892
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1892 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration of multi-factor authentication for staff access to the organisation's online customer services; Access review of staff accounts on customer service platforms

ISM-1893
Essential Eight, Maturity Level One

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1893 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Multi-factor settings for staff accounts on third-party customer service platforms; Vendor attestation or admin console export showing enforcement

ISM-1873
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option. Required at Maturity Level Two of the Multi-factor authentication mitigation strategy (Appendix B); ISM control ISM-1873 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1874 (phishing-resistant multi-factor authentication for customers).

evidence an assessor asks for Customer authentication options showing a phishing-resistant option is offered; Customer help material describing the option

ISM-1874
Essential Eight

Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1874 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Customer authentication configuration requiring phishing-resistant methods; Customer sign-in logs showing method used

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
ISM-1173
Essential Eight, Maturity Level Two

Multi-factor authentication is used to authenticate privileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1173 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enforcing multi-factor authentication for privileged users of systems, including console and remote administration; Sample of privileged sign-in logs showing the second factor

ISM-0974
Essential Eight, Maturity Level Two

Multi-factor authentication is used to authenticate unprivileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-0974 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enforcing multi-factor authentication for unprivileged users signing in to systems (workstations and remote access); Coverage report of users enrolled

The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)

ClauseThe held text, and the evidence an assessor asks for
ISM-1682
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating users of systems is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1682 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration requiring phishing-resistant multi-factor authentication for users of systems; Enrolment report for security keys or platform authenticators

ISM-1872
Essential Eight, Maturity Level Two

Multi-factor authentication used for authenticating users of online services is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1872 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy requiring phishing-resistant methods (for example FIDO2 or certificate-based) for users of online services; Sign-in logs showing only phishing-resistant methods succeed

ISM-1894
Essential Eight

Multi-factor authentication used for authenticating users of data repositories is phishing-resistant. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1894 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration requiring phishing-resistant methods for data repository access; Sample of repository sign-ins showing method

Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time

ClauseThe held text, and the evidence an assessor asks for
ISM-1511
Essential Eight, Maturity Level One

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1511 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Backup policy setting frequency and retention by business criticality and continuity requirements; Backup job reports matching the policy

ISM-1810
Essential Eight, Maturity Level One

Backups of data, applications and settings are synchronised to enable restoration to a common point in time. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1810 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Backup schedule showing data, applications and settings synchronised to a common point in time; Restore point catalogue

Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them

ClauseThe held text, and the evidence an assessor asks for
ISM-1811
Essential Eight, Maturity Level One

Backups of data, applications and settings are retained in a secure and resilient manner. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1811 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Evidence backups are stored securely and resiliently (offline, immutable or separate copies); Storage configuration

ISM-1812
Essential Eight, Maturity Level One

Unprivileged user accounts cannot access backups belonging to other user accounts. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1812 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Backup repository permissions showing unprivileged accounts cannot reach other users' backups; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1814
Essential Eight, Maturity Level One

Unprivileged user accounts are prevented from modifying and deleting backups. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1814 in ASD's Essential Eight to ISM mapping (December 2023). The Maturity Level Three table words it: "Unprivileged accounts are prevented from modifying and deleting backups."

evidence an assessor asks for Permissions preventing unprivileged accounts modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1813
Essential Eight

Unprivileged user accounts cannot access their own backups. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1813 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration preventing unprivileged accounts accessing their own backups; Dated record of an assessor's attempt to defeat the setting, with the outcome

Administrator accounts (other than the backup administrator) cannot change or delete backups

ClauseThe held text, and the evidence an assessor asks for
ISM-1705
Essential Eight, Maturity Level Two

Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1705 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators accessing other users' backups; List of backup administrator accounts

ISM-1707
Essential Eight, Maturity Level Two

Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1707 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1706
Essential Eight

Privileged user accounts (excluding backup administrator accounts) cannot access their own backups. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1706 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration preventing privileged accounts other than backup administrators accessing their own backups; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1708
Essential Eight

Backup administrator accounts are prevented from modifying and deleting backups during their retention period. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1708 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Immutability or retention lock preventing backup administrators modifying or deleting backups during retention; Retention lock configuration

Restoring from backup is tested as part of a disaster recovery exercise

ClauseThe held text, and the evidence an assessor asks for
ISM-1515
Essential Eight, Maturity Level One

Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1515 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Disaster recovery exercise records with restoration to a common point in time; Test results and issues found

Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
ISM-1690
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1690 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within two weeks of release

evidence an assessor asks for Patch records for non-critical online service vulnerabilities showing application within two weeks of release; Exception register entries for any late items with compensating controls

ISM-1876
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1876 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Patch records for online services with vendor release date, severity or exploit status, and applied date; Vulnerability ticket showing critical items closed within 48 hours

ISM-1694
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1694 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within two weeks of release

evidence an assessor asks for Records of non-critical internet-facing operating system patches applied within two weeks; Exceptions with compensating controls for devices awaiting vendor fixes

ISM-1877
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1877 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Patch records for internet-facing server and network device operating systems with release date, criticality or exploit status and applied date; Emergency change records showing 48-hour application

Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
ISM-1691
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release. Required at Maturity Levels One and Two of the Patch applications mitigation strategy (Appendices A and B); ISM control ISM-1691 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1692 (48 hours when critical or exploited) and ISM-1901 (two weeks when non-critical).

The requirement's own words: within two weeks of release

evidence an assessor asks for Installed-version reports for office suites, browsers, email clients, PDF software and security products against vendor release dates; Deployment tool report showing successful installation within two weeks

ISM-1695
Essential Eight, Maturity Level One

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release. Required at Maturity Levels One and Two of the Patch operating systems mitigation strategy (Appendices A and B); ISM control ISM-1695 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1696 (48 hours when critical or exploited) and ISM-1902 (one month when non-critical).

The requirement's own words: within one month of release

evidence an assessor asks for Hotfix listings (for example command-line output) with install dates for workstations and internal servers; Deployment compliance report showing application within one month

ISM-1692
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-1692 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Records of critical or exploited vulnerabilities in office suites, browsers, email clients, PDF software and security products with 48-hour application; Emergency change records for out-of-cycle browser and office updates

ISM-1901
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-1901 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within two weeks of release

evidence an assessor asks for Records of non-critical vulnerabilities in the named application classes applied within two weeks of release; Deployment ring schedule showing the full estate completes within two weeks

ISM-1696
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1696 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Records of critical or exploited internal operating system vulnerabilities patched within 48 hours; Emergency change approvals for internal servers and workstations

ISM-1902
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1902 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within one month of release

evidence an assessor asks for Records of non-critical internal operating system patches applied within one month; Monthly patch compliance report for workstations and internal servers

ISM-1407
Essential Eight

The latest release, or the previous release, of operating systems are used. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1407 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Operating system release inventory showing each host on the latest or previous release; Upgrade plan for hosts approaching a two-release gap

ISM-1879
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1879 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Records of critical driver updates applied within 48 hours of release; Driver deployment tool reports

ISM-1697
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1697 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within one month of release

evidence an assessor asks for Records of non-critical driver updates applied within one month; Driver compliance report by model

ISM-1903
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1903 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within 48 hours of release

evidence an assessor asks for Records of critical firmware updates applied within 48 hours; Out-of-band management logs showing firmware deployment dates

ISM-1904
Essential Eight

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1904 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within one month of release

evidence an assessor asks for Records of non-critical firmware updates applied within one month; Firmware compliance report across servers, workstations and network devices

Other business applications are patched within the timeframe in the requirement

ClauseThe held text, and the evidence an assessor asks for
ISM-1693
Essential Eight, Maturity Level Two

Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1693 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: within one month of release

evidence an assessor asks for Patch records for other applications showing application within one month of release; Vendor release tracking for line-of-business applications

Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements

ClauseThe held text, and the evidence an assessor asks for
ISM-1698
Essential Eight, Maturity Level One

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1698 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least daily

evidence an assessor asks for Daily scan schedule and last seven days of scan results for online services; Inventory of internet-facing online services in scan scope

ISM-1699
Essential Eight, Maturity Level One

A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1699 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least weekly

evidence an assessor asks for Weekly authenticated scan results for office suites, browsers and extensions, email clients, PDF software and security products; Scan policy naming those application classes

ISM-1807
Essential Eight, Maturity Level One

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1807 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Asset discovery tool schedule showing runs at least fortnightly; Latest discovery output reconciled to the vulnerability scanning target list

ISM-1808
Essential Eight, Maturity Level One

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1808 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Vulnerability scanner console showing the date of the last plugin or database update; Scanner licence and update configuration record

ISM-1701
Essential Eight, Maturity Level One

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1701 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least daily

evidence an assessor asks for Daily scan schedule and results for operating systems of internet-facing servers and network devices; List of internet-facing hosts and devices in daily scan scope

ISM-1702
Essential Eight, Maturity Level One

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1702 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan results for workstation, non-internet-facing server and internal network device operating systems; Credentialed scan configuration for internal hosts

ISM-1700
Essential Eight, Maturity Level Two

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1700 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan results covering applications other than the named classes; Scan policy that includes line-of-business and other installed applications

ISM-1703
Essential Eight

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1703 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan results identifying missing driver updates; Driver inventory by device model

ISM-1900
Essential Eight

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1900 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: at least fortnightly

evidence an assessor asks for Fortnightly scan or tool output identifying missing firmware updates for servers, workstations and devices; Firmware version inventory by hardware model

Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed

ClauseThe held text, and the evidence an assessor asks for
ISM-1501
Essential Eight, Maturity Level One

Operating systems that are no longer supported by vendors are replaced. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1501 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Operating system version inventory (for example winver output or scanner OS fingerprinting) compared with vendor support lists; Replacement or upgrade records for operating systems that reached end of support

ISM-1704
Essential Eight, Maturity Level One

Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1704 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Software inventory of office suites, browsers and extensions, email clients, PDF software and security products checked against vendor support lifecycles; Evidence that the retired browser plug-in named in the requirement is removed (the removal hotfix or an equivalent record)

ISM-1905
Essential Eight, Maturity Level One

Online services that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1905 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Inventory of online services in use with vendor support status and end-of-support dates; Decommissioning records for online services that reached end of support

ISM-0304
Essential Eight

Applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-0304 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Complete software inventory checked against vendor support lifecycles for all other applications; Removal records for unsupported applications with dates

Administrators use a separate privileged account and environment for admin work only, with no internet or email on it

ClauseThe held text, and the evidence an assessor asks for
ISM-0445
Essential Eight, Maturity Level One

Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-0445 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for List of privileged users with their separate privileged accounts; Account naming standard and directory export

ISM-1175
Essential Eight, Maturity Level One

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1175 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Proxy, firewall or policy configuration blocking internet, email and web access for privileged accounts; List of privileged accounts explicitly authorised for online services

ISM-1380
Essential Eight, Maturity Level One

Privileged users use separate privileged and unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1380 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Architecture showing separate privileged and unprivileged operating environments; Evidence of dedicated administration workstations or virtual environments

ISM-1688
Essential Eight, Maturity Level One

Unprivileged user accounts cannot logon to privileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1688 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy or equivalent denying unprivileged accounts logon to privileged environments; Test results of an attempted unprivileged logon

ISM-1689
Essential Eight, Maturity Level One

Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1689 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy or equivalent denying privileged accounts logon to unprivileged workstations and servers; Logon event review showing no privileged logons to standard hosts

ISM-1883
Essential Eight, Maturity Level One

Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1883 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Approval records and scope for each privileged account authorised to access online services; Configuration limiting those accounts to the approved services

ISM-1387
Essential Eight, Maturity Level Two

Administrative activities are conducted through jump servers. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1387 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Network rules forcing administration traffic through jump servers; Jump server access logs

ISM-1687
Essential Eight, Maturity Level Two

Privileged operating environments are not virtualised within unprivileged operating environments. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1687 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Virtualisation architecture showing privileged environments are not hosted inside unprivileged ones; Configuration review of administration virtual machines

ISM-1898
Essential Eight

Secure Admin Workstations are used in the performance of administrative activities. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1898 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Secure Admin Workstation build standard and inventory; Evidence administrative activities occur only from those workstations

ISM-1649
Essential Eight

Just-in-time administration is used for administering systems and applications. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1649 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Just-in-time elevation tool configuration and request logs; Report of standing privileged group membership (expected near zero)

Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked

ClauseThe held text, and the evidence an assessor asks for
ISM-1507
Essential Eight, Maturity Level One

Requests for privileged access to systems, applications and data repositories are validated when first requested. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1507 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Privileged access request forms or tickets with validation and approver; Sample of new privileged accounts traced to approved requests

ISM-1508
Essential Eight

Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1508 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Role-based privilege model with least-privilege role definitions; Access review showing privileges trimmed to duties

Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated

ClauseThe held text, and the evidence an assessor asks for
ISM-1647
Essential Eight, Maturity Level Two

Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1647 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: after 12 months unless revalidated

evidence an assessor asks for Revalidation records for privileged access at least every 12 months; Report of accounts disabled for lack of revalidation

ISM-1648
Essential Eight, Maturity Level Two

Privileged access to systems and applications is disabled after 45 days of inactivity. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1648 in ASD's Essential Eight to ISM mapping (December 2023).

The requirement's own words: after 45 days of inactivity

evidence an assessor asks for Automated rule disabling privileged access after 45 days of inactivity; Inactive privileged account report

Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed

ClauseThe held text, and the evidence an assessor asks for
ISM-1685
Essential Eight, Maturity Level Two

Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1685 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Privileged access management vault records for break glass, local administrator and service account credentials; Local administrator password solution configuration and rotation logs

ISM-1686
Essential Eight

Credential Guard functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1686 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enabling Credential Guard; Device compliance report showing it running

ISM-1861
Essential Eight

Local Security Authority protection functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1861 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enabling Local Security Authority protection; Compliance report across workstations and servers

ISM-1896
Essential Eight

Memory integrity functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1896 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration showing memory integrity (hypervisor-protected code integrity) enabled; Device compliance report

ISM-1897
Essential Eight

Remote Credential Guard functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1897 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enabling Remote Credential Guard for remote desktop sessions; Remote administration procedure requiring it

Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders

ClauseThe held text, and the evidence an assessor asks for
ISM-0843
Essential Eight, Maturity Level One

Application control is implemented on workstations. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-0843 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Application control policy deployed to all workstations with enforcement mode; Compliance report showing coverage

ISM-1657
Essential Eight, Maturity Level One

Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1657 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Approved set covering executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets; Test results for each file type

ISM-1870
Essential Eight, Maturity Level One

Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1870 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rules preventing execution from user profiles and temporary folders used by the operating system, browsers and email clients; Test of an executable launched from a user profile folder

Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review

ClauseThe held text, and the evidence an assessor asks for
ISM-1490
Essential Eight, Maturity Level Two

Application control is implemented on internet-facing servers. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1490 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Application control policy on internet-facing servers in enforcement mode; Server coverage report

ISM-1544
Essential Eight, Maturity Level Two

Microsoft’s recommended application blocklist is implemented. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1544 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for The vendor's recommended application blocklist deployed in the ruleset; Version date of the blocklist in use

ISM-1582
Essential Eight, Maturity Level Two

Application control rulesets are validated on an annual or more frequent basis. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1582 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Ruleset validation records at least annually with reviewer and changes; Removal of obsolete allow rules

ISM-1871
Essential Eight, Maturity Level Two

Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1871 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rules applying application control across all locations, not only user profiles and temporary folders; Test of execution from other writable locations

ISM-1656
Essential Eight

Application control is implemented on non-internet-facing servers. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1656 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Application control policy on non-internet-facing servers in enforcement mode; Server coverage report

ISM-1658
Essential Eight

Application control restricts the execution of drivers to an organisation-approved set. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1658 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Driver allow rules restricting execution to an approved set; Test of an unapproved driver load

ISM-1659
Essential Eight

Microsoft’s vulnerable driver blocklist is implemented. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1659 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for The vendor's vulnerable driver blocklist enabled, and its version; Compliance report across hosts

ISM-1660
Essential Eight, Maturity Level Two

Allowed and blocked application control events are centrally logged. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1660 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central logging of allowed and blocked application control events; Sample of blocked events from workstations and servers

Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings

ClauseThe held text, and the evidence an assessor asks for
ISM-1488
Essential Eight, Maturity Level One

Microsoft Office macros in files originating from the internet are blocked. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1488 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy blocking macros in files from the internet (mark of the web); Test with a downloaded macro-enabled file

ISM-1489
Essential Eight, Maturity Level One

Microsoft Office macro security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1489 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy locking macro security settings so users cannot change them; Screenshot of greyed-out Trust Center settings

ISM-1671
Essential Eight, Maturity Level One

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1671 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy disabling macros for users without a demonstrated business requirement; Register of users approved for macros with justification

ISM-1672
Essential Eight, Maturity Level One

Microsoft Office macro antivirus scanning is enabled. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1672 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enabling macro antivirus scanning (AMSI integration); Test with a benign detection sample

ISM-1673
Essential Eight, Maturity Level Two

Microsoft Office macros are blocked from making Win32 API calls. Required at Maturity Levels Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices B and C); ISM control ISM-1673 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Attack surface reduction rule blocking Win32 API calls from Office macros in block mode; Rule compliance report

ISM-1487
Essential Eight

Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1487 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Access control lists on Trusted Locations restricting write access to responsible privileged users; List of those users

ISM-1674
Essential Eight

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1674 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy allowing only macros in a sandbox, a Trusted Location or signed by a trusted publisher; Test showing other macros fail to run

ISM-1675
Essential Eight

Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1675 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing users enabling macros signed by untrusted publishers from the Message Bar or Backstage View; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1676
Essential Eight

Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1676 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Annual validation record of the trusted publisher list; Publisher removals recorded

ISM-1890
Essential Eight

Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1890 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Macro review records showing checks for malicious code before signing or placement in Trusted Locations; Reviewer sign-off

ISM-1891
Essential Eight

Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1891 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy requiring V3 signatures for macros to be enabled; Test with a non-V3 signed macro

Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed

ClauseThe held text, and the evidence an assessor asks for
ISM-1485
Essential Eight, Maturity Level One

Web browsers do not process web advertisements from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1485 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser or network control blocking web advertisements from the internet; Configuration export

ISM-1486
Essential Eight, Maturity Level One

Web browsers do not process Java from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1486 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser policy blocking the plug-in code the requirement names from the internet; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1585
Essential Eight, Maturity Level One

Web browser security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1585 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy locking browser security settings; User test showing settings cannot be changed

ISM-1654
Essential Eight, Maturity Level One

Internet Explorer 11 is disabled or removed. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1654 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Evidence the retired built-in browser the requirement names is disabled or removed across hosts; Endpoint management compliance report showing the setting applied on each in-scope host

Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted

ClauseThe held text, and the evidence an assessor asks for
ISM-1412
Essential Eight, Maturity Level Two

Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1412 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser hardening baseline based on ASD and vendor guidance; Compliance report against the baseline

ISM-1542
Essential Eight, Maturity Level Two

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1542 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing activation of OLE packages in Office; Test with an embedded package

ISM-1667
Essential Eight, Maturity Level Two

Microsoft Office is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1667 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Attack surface reduction rule blocking Office from creating child processes in block mode; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1668
Essential Eight, Maturity Level Two

Microsoft Office is blocked from creating executable content. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1668 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rule blocking Office from creating executable content; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1669
Essential Eight, Maturity Level Two

Microsoft Office is blocked from injecting code into other processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1669 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rule blocking Office from injecting code into other processes; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1670
Essential Eight, Maturity Level Two

PDF software is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1670 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Control blocking PDF software from creating child processes; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1823
Essential Eight, Maturity Level Two

Office productivity suite security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1823 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing users changing Office security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1824
Essential Eight, Maturity Level Two

PDF software security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1824 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing users changing PDF software security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1859
Essential Eight, Maturity Level Two

Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1859 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Office hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1860
Essential Eight, Maturity Level Two

PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1860 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for PDF software hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1621
Essential Eight

Windows PowerShell 2.0 is disabled or removed. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1621 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Evidence the old scripting engine version the requirement names is disabled or removed; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1622
Essential Eight

PowerShell is configured to use Constrained Language Mode. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1622 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration placing the scripting shell in its constrained language mode (for example through application control); Test showing language mode for standard users

ISM-1655
Essential Eight

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1655 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Evidence the old application framework versions the requirement names are disabled or removed; Exception register for applications that need it

Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner

ClauseThe held text, and the evidence an assessor asks for
ISM-1509
Essential Eight, Maturity Level Two

Privileged access events are centrally logged. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1509 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central log platform showing privileged access events ingested; Sample of privileged sign-ins traced end to end

ISM-1650
Essential Eight, Maturity Level Two

Privileged user account and security group management events are centrally logged. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1650 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central logging of privileged account and security group changes; Alert rules for additions to administrative groups

ISM-1815
Essential Eight, Maturity Level Two

Event logs are protected from unauthorised modification and deletion. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1815 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for Integrity protection and access restrictions on the store of privileged access event logs; List of accounts able to delete those logs

ISM-1906
Essential Eight, Maturity Level Two

Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1906 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for Detection rules analysing privileged activity on internet-facing servers; Triage records with timestamps

ISM-1228
Essential Eight, Maturity Level Two

Cyber security events are analysed in a timely manner to identify cyber security incidents. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1228 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for Analysis records of privileged access anomalies (new admin accounts, unusual hours) with outcomes; Timeliness metrics for privileged-activity alerts

ISM-1683
Essential Eight, Maturity Level Two

Successful and unsuccessful multi-factor authentication events are centrally logged. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1683 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central log platform showing successful and unsuccessful multi-factor events ingested; Retention setting for authentication logs

ISM-1623
Essential Eight, Maturity Level Two

PowerShell module logging, script block logging and transcription events are centrally logged. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1623 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central logging of the scripting shell's module logging, script block logging and transcription; Sample events in the log platform

ISM-1889
Essential Eight, Maturity Level Two

Command line process creation events are centrally logged. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1889 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central logging of command line process creation events; Audit policy showing command line capture enabled

ISM-0109
Essential Eight

Event logs from workstations are analysed in a timely manner to detect cyber security events. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-0109 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Application control, so it is assessed for the events this strategy generates.

evidence an assessor asks for Analysis of workstation application control events; Triage records with timestamps

ISM-1907
Essential Eight

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1907 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Application control, so it is assessed for the events this strategy generates.

evidence an assessor asks for Analysis rules on application control events from non-internet-facing servers; Alert triage tickets with detection time, analyst and outcome

There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names

ClauseThe held text, and the evidence an assessor asks for
ISM-1819
Essential Eight, Maturity Level Two

Following the identification of a cyber security incident, the cyber security incident response plan is enacted. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1819 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for Incident response plan activation for a privileged account incident; Post-incident review record

ISM-0123
Essential Eight, Maturity Level Two

Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-0123 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for Incident records for privileged account misuse showing CISO or delegate notification; Escalation matrix

ISM-0140
Essential Eight, Maturity Level Two

Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-0140 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates.

evidence an assessor asks for ASD ReportCyber references for privileged account compromise incidents; Written procedure naming who submits reports to ASD and when

Questions

When does Essential Eight apply here?
The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.
Which edition is held?
Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023)
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.