The Essential Eight.
The Essential Eight.
What is the ASD Essential Eight?
The Essential Eight is a set of prioritised cybersecurity mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect their internet-connected IT networks from common cyber threats.
The Essential Eight provides a practical baseline for improving cybersecurity and making it harder for attackers to compromise systems, steal information or disrupt business operations.
The Essential Eight consists of eight key mitigation strategies:
Keep applications up to date and address vulnerabilities promptly. Particular attention should be given to internet-facing services, web browsers, email clients, office applications, PDF software and other applications that regularly interact with untrusted content.
Ensure operating systems are kept supported and up to date across workstations, servers and network devices. Higher-priority vulnerabilities, particularly those affecting internet-facing systems, require rapid remediation.
Use multi-factor authentication (MFA) to provide additional protection for user accounts and online services. Stronger, phishing-resistant forms of MFA should be used where required by the applicable maturity level.
Limit administrator access to only those users who need it and only for as long as it is required. Privileged accounts should be separately managed and protected to reduce the impact of compromised credentials.
Control which applications, scripts and other executable content are permitted to run on systems. Application control helps prevent malicious or unauthorised software from executing.
Restrict the use of Microsoft Office macros, particularly macros originating from untrusted or internet-based sources. This reduces a common pathway for malware and other malicious code.
Harden commonly used applications such as web browsers, Microsoft Office and PDF software to reduce opportunities for attackers to exploit application features or vulnerabilities.
Regularly back up important data, applications and configuration information. Backups should be securely stored, protected from unauthorised modification or deletion, and regularly tested to confirm that systems and data can actually be restored.
The Essential Eight Maturity Model provides four maturity levels:
Maturity Level 0 – identifies weaknesses in an organisation's overall cybersecurity posture.
Maturity Level 1 – helps protect against common, opportunistic attacks using commodity tools and techniques.
Maturity Level 2 – provides stronger protection against attackers who are more capable and willing to invest additional effort in targeting an organisation.
Maturity Level 3 – provides a higher level of protection against more adaptive and sophisticated attackers.
Organisations should determine an appropriate target maturity level based on their environment, the information they hold, their exposure to threats and the potential consequences of a cybersecurity incident.
The Essential Eight should be implemented as a complete set rather than treating individual strategies in isolation.
Implementing the Essential Eight can seem complicated, particularly for small and medium-sized businesses that may not have dedicated cybersecurity staff.
Softrade can help your organisation assess its current cybersecurity environment, identify gaps and develop a practical plan to improve your Essential Eight maturity.
We can assist with areas such as:
Microsoft 365 and cloud security
Multi-factor authentication
Endpoint and operating system security
Application and software management
Administrator and privileged account controls
Backup and recovery
Security configuration and hardening
Ongoing monitoring and support
Our approach is practical and risk-based, helping you improve your cybersecurity without introducing unnecessary complexity.
Contact Softrade to discuss your current environment and the steps you can take to strengthen your organisation's cybersecurity.
The Essential Eight is developed and maintained by the Australian Signals Directorate (ASD). The Essential Eight provides a baseline of preventative measures and does not address every cybersecurity threat. Organisations should consider additional security controls appropriate to their environment and risk profile.
The November 2023 model introduced stronger patching requirements. For example, at Maturity Level 1, critical vulnerabilities in internet-facing services are to be patched, updated or otherwise mitigated within 48 hours where the vendor assesses the vulnerability as critical or a working exploit exists. Important internet-facing operating-system vulnerabilities have similar requirements.
The MFA requirements have also become considerably stronger, including requirements around phishing-resistant MFA at higher maturity levels.