All ML2 requirements plus: Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties. Secure Admin Workstations are used in the performance of administrative activities. Just-in-time administration is used for administering systems and applications. Memory integrity functionality is enabled. Local Security Authority protection functionality is enabled. Credential Guard functionality is enabled. Remote Credential Guard functionality is enabled. Event logs from non-internet-facing servers and workstations are analysed in a timely manner to detect cyber security events.
ACSC Essential Eight ADMIN-ML3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ACSC Essential Eight your existing evidence covers. Hold FedRAMP Moderate and 18 of 24 ACSC Essential Eight controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.