ASIC Cyber Resilience Good Practices
Protective Measures and Controls

ASIC Cyber Resilience Good Practices ASIC-CR-PR-1: Implement the ASD Essential Eight

Implement the Australian Signals Directorate's Essential Eight strategies to mitigate targeted cyber incidents, and self-assess maturity using the Essential Eight Maturity Model.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 17 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 8 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-APP-ML1 Application Control (ML1)
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-UAH-ML1 User Application Hardening - Maturity Level 1
  • ASD37-01 Application control (Essential)
  • ASD37-02 Patch applications (Essential)
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Protective Measures and Controls

Query this from an agent

The graph holds this control, the 17 it maps to, and the evidence behind each claim, over MCP and REST.