Knowledge / frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

ESSENTIAL EIGHT / ASD01App control02Patch apps03Office macros04App hardening05Restrict admin06Patch OS07MFA08BackupsMaturity 0 to 3. Pick a level you can hold, then hold it.

The Essential Eight is the Australian Signals Directorate's set of mitigation strategies that stop a large share of commodity intrusion. It is not a full information security program. It is the floor.

The eight: application control; patch applications; configure Microsoft Office macro settings; user application hardening; restrict administrative privileges; patch operating systems; multi-factor authentication; regular backups.

Maturity levels run from 0 (not aligned) to 3. Most organisations fail by claiming level 2 on paper and operating at 0 in the bits. Pick a level, evidence it, then move.

Use it with the ISM, not instead of it. Essential Eight is the short list; the ISM is the catalogue.