Essential Eight evidence
How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.
Essential Eight is ASD's floor of eight mitigation strategies. Maturity runs from 0 to 3. ASD's Commonwealth posture reporting is explicit that a network's overall maturity equals its least mature strategy. If application control is at 0, you are at 0, even if MFA looks pretty.
Evidence is not a slide. For each strategy, name the scope (which workstations, which servers, which identity plane), the target maturity, the control as configured, the date you last checked, and the owner. Exceptions expire. A policy PDF with no corresponding configuration export is a wish.
What 'show you did it' looks like in practice: application control — the allow list source, the last change, and what happens to an unsigned binary. Patch applications and operating systems — time-to-patch for internet-facing and known-exploited, not a quarterly average. Macros — the actual setting, not the standard operating procedure. Admin restriction — the list of privileged accounts and the last access review. MFA — coverage of privileged, remote, and email, and whether it is phishing-resistant. Backups — the last restore test, not the last backup job.
PSPF, for non-corporate Commonwealth entities, has required Essential Eight to at least Maturity Level 2 since July 2022. Industry can use the same evidence standard without pretending to be an NCCE. Claim only the maturity you can put a file against. Then go and lift the weakest strategy. That is the work.
ASD's assessment process guide (October 2024) is the evidence standard. An assessment has four stages: plan and prepare, fix the scope (the assessment boundary) and the approach, test the controls on each mitigation strategy, then write the security assessment report. The Essential Eight is implemented and assessed as a package. Do not start a Maturity Level 2 assessment until you have demonstrated Maturity Level 1, and the same step from 2 to 3.
Evidence quality is a ladder. Excellent is a simulated activity that shows the control actually fires, for example trying to run a test application against application control. Good is reading the live configuration through the system's own interface. Fair is a copy of that configuration, a report or a screenshot. Poor is a policy PDF or someone saying they do it. Seek the highest quality that is reasonably practicable. A compensating control only counts if it gives equivalent protection against the same tradecraft the maturity level is meant to stop.
Fact source: ASD, Essential Eight assessment process guide.
