Tools / Essential Eight

Essential Eight quick reference

ASD baseline. Maturity 0 to 3. Claim only what you can evidence. Source: cyber.gov.au.

ESSENTIAL EIGHT / ASD01App control02Patch apps03Office macros04App hardening05Restrict admin06Patch OS07MFA08BackupsMaturity 0 to 3. Pick a level you can hold, then hold it.
#Strategy
01Application control
Only approved software runs. Start on workstations, then servers.
02Patch applications
Internet-facing and KEV first. Hours and days, not quarters.
03Microsoft Office macros
Block from the internet. Signed macros only if you must.
04User application hardening
Turn off unused features in browsers and office suites.
05Restrict admin privileges
No standing admin. Separate accounts. Log use.
06Patch operating systems
Same as apps. Firmware and hypervisors count.
07Multi-factor authentication
Privileged, remote, and email. Prefer phishing-resistant.
08Regular backups
Disconnected or immutable. Restore tested on a calendar.

How to use this without lying

Pick a target maturity for a defined scope (e.g. Windows workstations). Evidence each strategy. Exceptions expire. Do not average eight scores into a single vanity number.

Official Essential Eight (ACSC)