ACSC Essential Eight
The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.
edition Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023). 126 requirements cited here. Every Essential Eight clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1504 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1504 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Identity provider policy enforcing multi-factor authentication for the organisation's online services holding sensitive data; List of those online services mapped to the policy |
| ISM-1679 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1679 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Inventory of third-party online services processing sensitive data with multi-factor authentication status; Screenshots or configuration exports of multi-factor enforcement at each service |
| ISM-1680 Essential Eight, Maturity Level One | Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1680 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Inventory of third-party services holding non-sensitive data with multi-factor availability and status; Record of services where multi-factor authentication is not offered |
| ISM-1401 Essential Eight, Maturity Level One | Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1401 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Authentication policy listing permitted factor combinations; Evidence that knowledge-only or two knowledge factors are not accepted |
| ISM-1505 Essential Eight | Multi-factor authentication is used to authenticate users of data repositories. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1505 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enforcing multi-factor authentication for users of data repositories (databases, file stores, document systems); Repository list mapped to authentication method |
Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1681 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1681 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Customer authentication flow showing a second factor for services holding sensitive customer data; Customer enrolment statistics |
| ISM-1892 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1892 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration of multi-factor authentication for staff access to the organisation's online customer services; Access review of staff accounts on customer service platforms |
| ISM-1893 Essential Eight, Maturity Level One | Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1893 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Multi-factor settings for staff accounts on third-party customer service platforms; Vendor attestation or admin console export showing enforcement |
| ISM-1873 Essential Eight, Maturity Level Two | Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option. Required at Maturity Level Two of the Multi-factor authentication mitigation strategy (Appendix B); ISM control ISM-1873 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1874 (phishing-resistant multi-factor authentication for customers). evidence an assessor asks for Customer authentication options showing a phishing-resistant option is offered; Customer help material describing the option |
| ISM-1874 Essential Eight | Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1874 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Customer authentication configuration requiring phishing-resistant methods; Customer sign-in logs showing method used |
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1173 Essential Eight, Maturity Level Two | Multi-factor authentication is used to authenticate privileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1173 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enforcing multi-factor authentication for privileged users of systems, including console and remote administration; Sample of privileged sign-in logs showing the second factor |
| ISM-0974 Essential Eight, Maturity Level Two | Multi-factor authentication is used to authenticate unprivileged users of systems. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-0974 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enforcing multi-factor authentication for unprivileged users signing in to systems (workstations and remote access); Coverage report of users enrolled |
The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1682 Essential Eight, Maturity Level Two | Multi-factor authentication used for authenticating users of systems is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1682 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration requiring phishing-resistant multi-factor authentication for users of systems; Enrolment report for security keys or platform authenticators |
| ISM-1872 Essential Eight, Maturity Level Two | Multi-factor authentication used for authenticating users of online services is phishing-resistant. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1872 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy requiring phishing-resistant methods (for example FIDO2 or certificate-based) for users of online services; Sign-in logs showing only phishing-resistant methods succeed |
| ISM-1894 Essential Eight | Multi-factor authentication used for authenticating users of data repositories is phishing-resistant. Required at Maturity Level Three of the Multi-factor authentication mitigation strategy (Appendix C); ISM control ISM-1894 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration requiring phishing-resistant methods for data repository access; Sample of repository sign-ins showing method |
Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1511 Essential Eight, Maturity Level One | Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1511 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Backup policy setting frequency and retention by business criticality and continuity requirements; Backup job reports matching the policy |
| ISM-1810 Essential Eight, Maturity Level One | Backups of data, applications and settings are synchronised to enable restoration to a common point in time. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1810 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Backup schedule showing data, applications and settings synchronised to a common point in time; Restore point catalogue |
Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1811 Essential Eight, Maturity Level One | Backups of data, applications and settings are retained in a secure and resilient manner. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1811 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence backups are stored securely and resiliently (offline, immutable or separate copies); Storage configuration |
| ISM-1812 Essential Eight, Maturity Level One | Unprivileged user accounts cannot access backups belonging to other user accounts. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1812 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Backup repository permissions showing unprivileged accounts cannot reach other users' backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1814 Essential Eight, Maturity Level One | Unprivileged user accounts are prevented from modifying and deleting backups. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1814 in ASD's Essential Eight to ISM mapping (December 2023). The Maturity Level Three table words it: "Unprivileged accounts are prevented from modifying and deleting backups." evidence an assessor asks for Permissions preventing unprivileged accounts modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1813 Essential Eight | Unprivileged user accounts cannot access their own backups. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1813 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration preventing unprivileged accounts accessing their own backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
Administrator accounts (other than the backup administrator) cannot change or delete backups
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1705 Essential Eight, Maturity Level Two | Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1705 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators accessing other users' backups; List of backup administrator accounts |
| ISM-1707 Essential Eight, Maturity Level Two | Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1707 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Permissions preventing privileged accounts other than backup administrators modifying or deleting backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1706 Essential Eight | Privileged user accounts (excluding backup administrator accounts) cannot access their own backups. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1706 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration preventing privileged accounts other than backup administrators accessing their own backups; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1708 Essential Eight | Backup administrator accounts are prevented from modifying and deleting backups during their retention period. Required at Maturity Level Three of the Regular backups mitigation strategy (Appendix C); ISM control ISM-1708 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Immutability or retention lock preventing backup administrators modifying or deleting backups during retention; Retention lock configuration |
Restoring from backup is tested as part of a disaster recovery exercise
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1515 Essential Eight, Maturity Level One | Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises. Required at Maturity Levels One, Two and Three of the Regular backups mitigation strategy (Appendices A, B and C); ISM control ISM-1515 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Disaster recovery exercise records with restoration to a common point in time; Test results and issues found |
Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1690 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1690 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within two weeks of release evidence an assessor asks for Patch records for non-critical online service vulnerabilities showing application within two weeks of release; Exception register entries for any late items with compensating controls |
| ISM-1876 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1876 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Patch records for online services with vendor release date, severity or exploit status, and applied date; Vulnerability ticket showing critical items closed within 48 hours |
| ISM-1694 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1694 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within two weeks of release evidence an assessor asks for Records of non-critical internet-facing operating system patches applied within two weeks; Exceptions with compensating controls for devices awaiting vendor fixes |
| ISM-1877 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1877 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Patch records for internet-facing server and network device operating systems with release date, criticality or exploit status and applied date; Emergency change records showing 48-hour application |
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1691 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release. Required at Maturity Levels One and Two of the Patch applications mitigation strategy (Appendices A and B); ISM control ISM-1691 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1692 (48 hours when critical or exploited) and ISM-1901 (two weeks when non-critical). The requirement's own words: within two weeks of release evidence an assessor asks for Installed-version reports for office suites, browsers, email clients, PDF software and security products against vendor release dates; Deployment tool report showing successful installation within two weeks |
| ISM-1695 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release. Required at Maturity Levels One and Two of the Patch operating systems mitigation strategy (Appendices A and B); ISM control ISM-1695 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1696 (48 hours when critical or exploited) and ISM-1902 (one month when non-critical). The requirement's own words: within one month of release evidence an assessor asks for Hotfix listings (for example command-line output) with install dates for workstations and internal servers; Deployment compliance report showing application within one month |
| ISM-1692 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-1692 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Records of critical or exploited vulnerabilities in office suites, browsers, email clients, PDF software and security products with 48-hour application; Emergency change records for out-of-cycle browser and office updates |
| ISM-1901 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-1901 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within two weeks of release evidence an assessor asks for Records of non-critical vulnerabilities in the named application classes applied within two weeks of release; Deployment ring schedule showing the full estate completes within two weeks |
| ISM-1696 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1696 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Records of critical or exploited internal operating system vulnerabilities patched within 48 hours; Emergency change approvals for internal servers and workstations |
| ISM-1902 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1902 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within one month of release evidence an assessor asks for Records of non-critical internal operating system patches applied within one month; Monthly patch compliance report for workstations and internal servers |
| ISM-1407 Essential Eight | The latest release, or the previous release, of operating systems are used. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1407 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Operating system release inventory showing each host on the latest or previous release; Upgrade plan for hosts approaching a two-release gap |
| ISM-1879 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1879 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Records of critical driver updates applied within 48 hours of release; Driver deployment tool reports |
| ISM-1697 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1697 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within one month of release evidence an assessor asks for Records of non-critical driver updates applied within one month; Driver compliance report by model |
| ISM-1903 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1903 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within 48 hours of release evidence an assessor asks for Records of critical firmware updates applied within 48 hours; Out-of-band management logs showing firmware deployment dates |
| ISM-1904 Essential Eight | Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1904 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within one month of release evidence an assessor asks for Records of non-critical firmware updates applied within one month; Firmware compliance report across servers, workstations and network devices |
Other business applications are patched within the timeframe in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1693 Essential Eight, Maturity Level Two | Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1693 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within one month of release evidence an assessor asks for Patch records for other applications showing application within one month of release; Vendor release tracking for line-of-business applications |
Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1698 Essential Eight, Maturity Level One | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1698 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least daily evidence an assessor asks for Daily scan schedule and last seven days of scan results for online services; Inventory of internet-facing online services in scan scope |
| ISM-1699 Essential Eight, Maturity Level One | A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1699 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least weekly evidence an assessor asks for Weekly authenticated scan results for office suites, browsers and extensions, email clients, PDF software and security products; Scan policy naming those application classes |
| ISM-1807 Essential Eight, Maturity Level One | An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1807 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Asset discovery tool schedule showing runs at least fortnightly; Latest discovery output reconciled to the vulnerability scanning target list |
| ISM-1808 Essential Eight, Maturity Level One | A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1808 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Vulnerability scanner console showing the date of the last plugin or database update; Scanner licence and update configuration record |
| ISM-1701 Essential Eight, Maturity Level One | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1701 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least daily evidence an assessor asks for Daily scan schedule and results for operating systems of internet-facing servers and network devices; List of internet-facing hosts and devices in daily scan scope |
| ISM-1702 Essential Eight, Maturity Level One | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1702 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan results for workstation, non-internet-facing server and internal network device operating systems; Credentialed scan configuration for internal hosts |
| ISM-1700 Essential Eight, Maturity Level Two | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1700 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan results covering applications other than the named classes; Scan policy that includes line-of-business and other installed applications |
| ISM-1703 Essential Eight | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1703 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan results identifying missing driver updates; Driver inventory by device model |
| ISM-1900 Essential Eight | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware. Required at Maturity Level Three of the Patch operating systems mitigation strategy (Appendix C); ISM control ISM-1900 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: at least fortnightly evidence an assessor asks for Fortnightly scan or tool output identifying missing firmware updates for servers, workstations and devices; Firmware version inventory by hardware model |
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1501 Essential Eight, Maturity Level One | Operating systems that are no longer supported by vendors are replaced. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1501 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Operating system version inventory (for example winver output or scanner OS fingerprinting) compared with vendor support lists; Replacement or upgrade records for operating systems that reached end of support |
| ISM-1704 Essential Eight, Maturity Level One | Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1704 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Software inventory of office suites, browsers and extensions, email clients, PDF software and security products checked against vendor support lifecycles; Evidence that the retired browser plug-in named in the requirement is removed (the removal hotfix or an equivalent record) |
| ISM-1905 Essential Eight, Maturity Level One | Online services that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1905 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Inventory of online services in use with vendor support status and end-of-support dates; Decommissioning records for online services that reached end of support |
| ISM-0304 Essential Eight | Applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Level Three of the Patch applications mitigation strategy (Appendix C); ISM control ISM-0304 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Complete software inventory checked against vendor support lifecycles for all other applications; Removal records for unsupported applications with dates |
Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-0445 Essential Eight, Maturity Level One | Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-0445 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for List of privileged users with their separate privileged accounts; Account naming standard and directory export |
| ISM-1175 Essential Eight, Maturity Level One | Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1175 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Proxy, firewall or policy configuration blocking internet, email and web access for privileged accounts; List of privileged accounts explicitly authorised for online services |
| ISM-1380 Essential Eight, Maturity Level One | Privileged users use separate privileged and unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1380 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Architecture showing separate privileged and unprivileged operating environments; Evidence of dedicated administration workstations or virtual environments |
| ISM-1688 Essential Eight, Maturity Level One | Unprivileged user accounts cannot logon to privileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1688 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Group policy or equivalent denying unprivileged accounts logon to privileged environments; Test results of an attempted unprivileged logon |
| ISM-1689 Essential Eight, Maturity Level One | Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1689 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Group policy or equivalent denying privileged accounts logon to unprivileged workstations and servers; Logon event review showing no privileged logons to standard hosts |
| ISM-1883 Essential Eight, Maturity Level One | Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1883 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Approval records and scope for each privileged account authorised to access online services; Configuration limiting those accounts to the approved services |
| ISM-1387 Essential Eight, Maturity Level Two | Administrative activities are conducted through jump servers. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1387 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Network rules forcing administration traffic through jump servers; Jump server access logs |
| ISM-1687 Essential Eight, Maturity Level Two | Privileged operating environments are not virtualised within unprivileged operating environments. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1687 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Virtualisation architecture showing privileged environments are not hosted inside unprivileged ones; Configuration review of administration virtual machines |
| ISM-1898 Essential Eight | Secure Admin Workstations are used in the performance of administrative activities. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1898 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Secure Admin Workstation build standard and inventory; Evidence administrative activities occur only from those workstations |
| ISM-1649 Essential Eight | Just-in-time administration is used for administering systems and applications. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1649 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Just-in-time elevation tool configuration and request logs; Report of standing privileged group membership (expected near zero) |
Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1507 Essential Eight, Maturity Level One | Requests for privileged access to systems, applications and data repositories are validated when first requested. Required at Maturity Levels One, Two and Three of the Restrict administrative privileges mitigation strategy (Appendices A, B and C); ISM control ISM-1507 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Privileged access request forms or tickets with validation and approver; Sample of new privileged accounts traced to approved requests |
| ISM-1508 Essential Eight | Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1508 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Role-based privilege model with least-privilege role definitions; Access review showing privileges trimmed to duties |
Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1647 Essential Eight, Maturity Level Two | Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1647 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: after 12 months unless revalidated evidence an assessor asks for Revalidation records for privileged access at least every 12 months; Report of accounts disabled for lack of revalidation |
| ISM-1648 Essential Eight, Maturity Level Two | Privileged access to systems and applications is disabled after 45 days of inactivity. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1648 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: after 45 days of inactivity evidence an assessor asks for Automated rule disabling privileged access after 45 days of inactivity; Inactive privileged account report |
Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1685 Essential Eight, Maturity Level Two | Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1685 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Privileged access management vault records for break glass, local administrator and service account credentials; Local administrator password solution configuration and rotation logs |
| ISM-1686 Essential Eight | Credential Guard functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1686 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enabling Credential Guard; Device compliance report showing it running |
| ISM-1861 Essential Eight | Local Security Authority protection functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1861 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enabling Local Security Authority protection; Compliance report across workstations and servers |
| ISM-1896 Essential Eight | Memory integrity functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1896 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration showing memory integrity (hypervisor-protected code integrity) enabled; Device compliance report |
| ISM-1897 Essential Eight | Remote Credential Guard functionality is enabled. Required at Maturity Level Three of the Restrict administrative privileges mitigation strategy (Appendix C); ISM control ISM-1897 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enabling Remote Credential Guard for remote desktop sessions; Remote administration procedure requiring it |
Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-0843 Essential Eight, Maturity Level One | Application control is implemented on workstations. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-0843 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Application control policy deployed to all workstations with enforcement mode; Compliance report showing coverage |
| ISM-1657 Essential Eight, Maturity Level One | Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1657 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Approved set covering executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets; Test results for each file type |
| ISM-1870 Essential Eight, Maturity Level One | Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1870 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rules preventing execution from user profiles and temporary folders used by the operating system, browsers and email clients; Test of an executable launched from a user profile folder |
Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1490 Essential Eight, Maturity Level Two | Application control is implemented on internet-facing servers. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1490 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Application control policy on internet-facing servers in enforcement mode; Server coverage report |
| ISM-1544 Essential Eight, Maturity Level Two | Microsoft’s recommended application blocklist is implemented. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1544 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for The vendor's recommended application blocklist deployed in the ruleset; Version date of the blocklist in use |
| ISM-1582 Essential Eight, Maturity Level Two | Application control rulesets are validated on an annual or more frequent basis. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1582 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Ruleset validation records at least annually with reviewer and changes; Removal of obsolete allow rules |
| ISM-1871 Essential Eight, Maturity Level Two | Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1871 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rules applying application control across all locations, not only user profiles and temporary folders; Test of execution from other writable locations |
| ISM-1656 Essential Eight | Application control is implemented on non-internet-facing servers. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1656 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Application control policy on non-internet-facing servers in enforcement mode; Server coverage report |
| ISM-1658 Essential Eight | Application control restricts the execution of drivers to an organisation-approved set. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1658 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Driver allow rules restricting execution to an approved set; Test of an unapproved driver load |
| ISM-1659 Essential Eight | Microsoft’s vulnerable driver blocklist is implemented. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1659 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for The vendor's vulnerable driver blocklist enabled, and its version; Compliance report across hosts |
| ISM-1660 Essential Eight, Maturity Level Two | Allowed and blocked application control events are centrally logged. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1660 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central logging of allowed and blocked application control events; Sample of blocked events from workstations and servers |
Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1488 Essential Eight, Maturity Level One | Microsoft Office macros in files originating from the internet are blocked. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1488 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy blocking macros in files from the internet (mark of the web); Test with a downloaded macro-enabled file |
| ISM-1489 Essential Eight, Maturity Level One | Microsoft Office macro security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1489 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy locking macro security settings so users cannot change them; Screenshot of greyed-out Trust Center settings |
| ISM-1671 Essential Eight, Maturity Level One | Microsoft Office macros are disabled for users that do not have a demonstrated business requirement. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1671 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Group policy disabling macros for users without a demonstrated business requirement; Register of users approved for macros with justification |
| ISM-1672 Essential Eight, Maturity Level One | Microsoft Office macro antivirus scanning is enabled. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1672 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enabling macro antivirus scanning (AMSI integration); Test with a benign detection sample |
| ISM-1673 Essential Eight, Maturity Level Two | Microsoft Office macros are blocked from making Win32 API calls. Required at Maturity Levels Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices B and C); ISM control ISM-1673 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Attack surface reduction rule blocking Win32 API calls from Office macros in block mode; Rule compliance report |
| ISM-1487 Essential Eight | Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1487 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Access control lists on Trusted Locations restricting write access to responsible privileged users; List of those users |
| ISM-1674 Essential Eight | Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1674 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy allowing only macros in a sandbox, a Trusted Location or signed by a trusted publisher; Test showing other macros fail to run |
| ISM-1675 Essential Eight | Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1675 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing users enabling macros signed by untrusted publishers from the Message Bar or Backstage View; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1676 Essential Eight | Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1676 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Annual validation record of the trusted publisher list; Publisher removals recorded |
| ISM-1890 Essential Eight | Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1890 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Macro review records showing checks for malicious code before signing or placement in Trusted Locations; Reviewer sign-off |
| ISM-1891 Essential Eight | Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View. Required at Maturity Level Three of the Restrict Microsoft Office macros mitigation strategy (Appendix C); ISM control ISM-1891 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy requiring V3 signatures for macros to be enabled; Test with a non-V3 signed macro |
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1485 Essential Eight, Maturity Level One | Web browsers do not process web advertisements from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1485 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser or network control blocking web advertisements from the internet; Configuration export |
| ISM-1486 Essential Eight, Maturity Level One | Web browsers do not process Java from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1486 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser policy blocking the plug-in code the requirement names from the internet; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1585 Essential Eight, Maturity Level One | Web browser security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1585 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy locking browser security settings; User test showing settings cannot be changed |
| ISM-1654 Essential Eight, Maturity Level One | Internet Explorer 11 is disabled or removed. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1654 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence the retired built-in browser the requirement names is disabled or removed across hosts; Endpoint management compliance report showing the setting applied on each in-scope host |
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1412 Essential Eight, Maturity Level Two | Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1412 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser hardening baseline based on ASD and vendor guidance; Compliance report against the baseline |
| ISM-1542 Essential Eight, Maturity Level Two | Microsoft Office is configured to prevent activation of Object Linking and Embedding packages. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1542 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing activation of OLE packages in Office; Test with an embedded package |
| ISM-1667 Essential Eight, Maturity Level Two | Microsoft Office is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1667 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Attack surface reduction rule blocking Office from creating child processes in block mode; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1668 Essential Eight, Maturity Level Two | Microsoft Office is blocked from creating executable content. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1668 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rule blocking Office from creating executable content; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1669 Essential Eight, Maturity Level Two | Microsoft Office is blocked from injecting code into other processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1669 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rule blocking Office from injecting code into other processes; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1670 Essential Eight, Maturity Level Two | PDF software is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1670 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Control blocking PDF software from creating child processes; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1823 Essential Eight, Maturity Level Two | Office productivity suite security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1823 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing users changing Office security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1824 Essential Eight, Maturity Level Two | PDF software security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1824 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing users changing PDF software security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1859 Essential Eight, Maturity Level Two | Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1859 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Office hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1860 Essential Eight, Maturity Level Two | PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1860 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for PDF software hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1621 Essential Eight | Windows PowerShell 2.0 is disabled or removed. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1621 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence the old scripting engine version the requirement names is disabled or removed; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1622 Essential Eight | PowerShell is configured to use Constrained Language Mode. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1622 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration placing the scripting shell in its constrained language mode (for example through application control); Test showing language mode for standard users |
| ISM-1655 Essential Eight | .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed. Required at Maturity Level Three of the User application hardening mitigation strategy (Appendix C); ISM control ISM-1655 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence the old application framework versions the requirement names are disabled or removed; Exception register for applications that need it |
Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1509 Essential Eight, Maturity Level Two | Privileged access events are centrally logged. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1509 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central log platform showing privileged access events ingested; Sample of privileged sign-ins traced end to end |
| ISM-1650 Essential Eight, Maturity Level Two | Privileged user account and security group management events are centrally logged. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1650 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central logging of privileged account and security group changes; Alert rules for additions to administrative groups |
| ISM-1815 Essential Eight, Maturity Level Two | Event logs are protected from unauthorised modification and deletion. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1815 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for Integrity protection and access restrictions on the store of privileged access event logs; List of accounts able to delete those logs |
| ISM-1906 Essential Eight, Maturity Level Two | Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1906 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for Detection rules analysing privileged activity on internet-facing servers; Triage records with timestamps |
| ISM-1228 Essential Eight, Maturity Level Two | Cyber security events are analysed in a timely manner to identify cyber security incidents. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1228 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for Analysis records of privileged access anomalies (new admin accounts, unusual hours) with outcomes; Timeliness metrics for privileged-activity alerts |
| ISM-1683 Essential Eight, Maturity Level Two | Successful and unsuccessful multi-factor authentication events are centrally logged. Required at Maturity Levels Two and Three of the Multi-factor authentication mitigation strategy (Appendices B and C); ISM control ISM-1683 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central log platform showing successful and unsuccessful multi-factor events ingested; Retention setting for authentication logs |
| ISM-1623 Essential Eight, Maturity Level Two | PowerShell module logging, script block logging and transcription events are centrally logged. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1623 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central logging of the scripting shell's module logging, script block logging and transcription; Sample events in the log platform |
| ISM-1889 Essential Eight, Maturity Level Two | Command line process creation events are centrally logged. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1889 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central logging of command line process creation events; Audit policy showing command line capture enabled |
| ISM-0109 Essential Eight | Event logs from workstations are analysed in a timely manner to detect cyber security events. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-0109 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Application control, so it is assessed for the events this strategy generates. evidence an assessor asks for Analysis of workstation application control events; Triage records with timestamps |
| ISM-1907 Essential Eight | Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events. Required at Maturity Level Three of the Application control mitigation strategy (Appendix C); ISM control ISM-1907 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Application control, so it is assessed for the events this strategy generates. evidence an assessor asks for Analysis rules on application control events from non-internet-facing servers; Alert triage tickets with detection time, analyst and outcome |
There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1819 Essential Eight, Maturity Level Two | Following the identification of a cyber security incident, the cyber security incident response plan is enacted. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-1819 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for Incident response plan activation for a privileged account incident; Post-incident review record |
| ISM-0123 Essential Eight, Maturity Level Two | Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-0123 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for Incident records for privileged account misuse showing CISO or delegate notification; Escalation matrix |
| ISM-0140 Essential Eight, Maturity Level Two | Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered. Required at Maturity Levels Two and Three of the Restrict administrative privileges mitigation strategy (Appendices B and C); ISM control ISM-0140 in ASD's Essential Eight to ISM mapping (December 2023). ASD lists this event logging and incident requirement under Restrict administrative privileges, so it is assessed for the events this strategy generates. evidence an assessor asks for ASD ReportCyber references for privileged account compromise incidents; Written procedure naming who submits reports to ASD and when |
Questions
- When does Essential Eight apply here?
- The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.
- Which edition is held?
- Essential Eight Maturity Model, November 2023 (ISM mapping, December 2023)
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.