Essential Eight evidence
How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.
Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.
6 entries
How to show you actually did the Essential Eight. Scope, artefact, date, owner. Overall maturity is the weakest strategy, not the average.
Infosec Registered Assessors Program. ASD-endorsed assessors test systems and cloud services against the ISM. An IRAP report is evidence, not an authorisation.
The Notifiable Data Breaches assessment and notify clocks. OAIC, not a breach tray. Thirty days to assess a suspicion; notify as soon as practicable once it is eligible.
The Australian Government protective security policy for non-corporate Commonwealth entities. Governance, information, personnel, physical — and a cyber floor that points at Essential Eight.
Security of Critical Infrastructure Act 2018, high level. Positive security obligations, cyber incident reporting, and extra duties if you are a System of National Significance.
You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, and ISM procurement sit on the same desk as the incident.
Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary