Back to Frameworks

ACSC Essential Eight

Australia
vEssential Eight Maturity Model, November 2023 (current as at 2026-09-30; cyber.gov.au page last updated 27 Nov 2023)
8 domains
152 controls

ASD's Essential Eight Maturity Model (November 2023): the eight mitigation strategies at Maturity Levels One to Three, each requirement as ASD states it with its ISM control and the levels it applies at, including the requirements that unsupported applications, online services and operating systems are removed or replaced.

Verified

ACSC Essential Eight is a compliance framework from Australia with 8 domains and 152 controls that map to 31 other frameworks. The largest domains are Restrict administrative privileges – ACSC Essential Eight (29 controls), User application hardening – ACSC Essential Eight (27 controls), Multi-factor authentication – ACSC Essential Eight (24 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Application control – ACSC Essential Eight

19 controls
Controls in the Application control – ACSC Essential Eight domain of ACSC Essential Eight — 19 controls
CodeTitle
acsc-essential-eight::E8-APP-ISM-0109Application control (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-APP-ISM-0123Application control (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
acsc-essential-eight::E8-APP-ISM-0140Application control (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
acsc-essential-eight::E8-APP-ISM-0843Application control (ISM-0843): Application control is implemented on workstations
acsc-essential-eight::E8-APP-ISM-1228Application control (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents
acsc-essential-eight::E8-APP-ISM-1490Application control (ISM-1490): Application control is implemented on internet-facing servers
acsc-essential-eight::E8-APP-ISM-1544Application control (ISM-1544): Microsoft’s recommended application blocklist is implemented
acsc-essential-eight::E8-APP-ISM-1582Application control (ISM-1582): Application control rulesets are validated on an annual or more frequent basis
acsc-essential-eight::E8-APP-ISM-1656Application control (ISM-1656): Application control is implemented on non-internet-facing servers
acsc-essential-eight::E8-APP-ISM-1657Application control (ISM-1657): Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set
acsc-essential-eight::E8-APP-ISM-1658Application control (ISM-1658): Application control restricts the execution of drivers to an organisation-approved set
acsc-essential-eight::E8-APP-ISM-1659Application control (ISM-1659): Microsoft’s vulnerable driver blocklist is implemented
acsc-essential-eight::E8-APP-ISM-1660Application control (ISM-1660): Allowed and blocked application control events are centrally logged
acsc-essential-eight::E8-APP-ISM-1815Application control (ISM-1815): Event logs are protected from unauthorised modification and deletion
acsc-essential-eight::E8-APP-ISM-1819Application control (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
acsc-essential-eight::E8-APP-ISM-1870Application control (ISM-1870): Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients
acsc-essential-eight::E8-APP-ISM-1871Application control (ISM-1871): Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients
acsc-essential-eight::E8-APP-ISM-1906Application control (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-APP-ISM-1907Application control (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events

Multi-factor authentication – ACSC Essential Eight

24 controls
Controls in the Multi-factor authentication – ACSC Essential Eight domain of ACSC Essential Eight — 24 controls
CodeTitle
acsc-essential-eight::E8-MFA-ISM-0109Multi-factor authentication (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-MFA-ISM-0123Multi-factor authentication (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
acsc-essential-eight::E8-MFA-ISM-0140Multi-factor authentication (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
acsc-essential-eight::E8-MFA-ISM-0974Multi-factor authentication (ISM-0974): Multi-factor authentication is used to authenticate unprivileged users of systems
acsc-essential-eight::E8-MFA-ISM-1173Multi-factor authentication (ISM-1173): Multi-factor authentication is used to authenticate privileged users of systems
acsc-essential-eight::E8-MFA-ISM-1228Multi-factor authentication (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents
acsc-essential-eight::E8-MFA-ISM-1401Multi-factor authentication (ISM-1401): Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are
acsc-essential-eight::E8-MFA-ISM-1504Multi-factor authentication (ISM-1504): Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data
acsc-essential-eight::E8-MFA-ISM-1505Multi-factor authentication (ISM-1505): Multi-factor authentication is used to authenticate users of data repositories
acsc-essential-eight::E8-MFA-ISM-1679Multi-factor authentication (ISM-1679): Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data
acsc-essential-eight::E8-MFA-ISM-1680Multi-factor authentication (ISM-1680): Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data
acsc-essential-eight::E8-MFA-ISM-1681Multi-factor authentication (ISM-1681): Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data
acsc-essential-eight::E8-MFA-ISM-1682Multi-factor authentication (ISM-1682): Multi-factor authentication used for authenticating users of systems is phishing-resistant
acsc-essential-eight::E8-MFA-ISM-1683Multi-factor authentication (ISM-1683): Successful and unsuccessful multi-factor authentication events are centrally logged
acsc-essential-eight::E8-MFA-ISM-1815Multi-factor authentication (ISM-1815): Event logs are protected from unauthorised modification and deletion
acsc-essential-eight::E8-MFA-ISM-1819Multi-factor authentication (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
acsc-essential-eight::E8-MFA-ISM-1872Multi-factor authentication (ISM-1872): Multi-factor authentication used for authenticating users of online services is phishing-resistant
acsc-essential-eight::E8-MFA-ISM-1873Multi-factor authentication (ISM-1873): Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option
acsc-essential-eight::E8-MFA-ISM-1874Multi-factor authentication (ISM-1874): Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant
acsc-essential-eight::E8-MFA-ISM-1892Multi-factor authentication (ISM-1892): Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data
acsc-essential-eight::E8-MFA-ISM-1893Multi-factor authentication (ISM-1893): Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data
acsc-essential-eight::E8-MFA-ISM-1894Multi-factor authentication (ISM-1894): Multi-factor authentication used for authenticating users of data repositories is phishing-resistant
acsc-essential-eight::E8-MFA-ISM-1906Multi-factor authentication (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-MFA-ISM-1907Multi-factor authentication (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events

Patch applications – ACSC Essential Eight

14 controls
Controls in the Patch applications – ACSC Essential Eight domain of ACSC Essential Eight — 14 controls
CodeTitle
acsc-essential-eight::E8-PATCHAPP-ISM-0304Patch applications (ISM-0304): Applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed
acsc-essential-eight::E8-PATCHAPP-ISM-1690Patch applications (ISM-1690): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
acsc-essential-eight::E8-PATCHAPP-ISM-1691Patch applications (ISM-1691): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release
acsc-essential-eight::E8-PATCHAPP-ISM-1692Patch applications (ISM-1692): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHAPP-ISM-1693Patch applications (ISM-1693): Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release
acsc-essential-eight::E8-PATCHAPP-ISM-1698Patch applications (ISM-1698): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services
acsc-essential-eight::E8-PATCHAPP-ISM-1699Patch applications (ISM-1699): A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products
acsc-essential-eight::E8-PATCHAPP-ISM-1700Patch applications (ISM-1700): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products
acsc-essential-eight::E8-PATCHAPP-ISM-1704Patch applications (ISM-1704): Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed
acsc-essential-eight::E8-PATCHAPP-ISM-1807Patch applications (ISM-1807): An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities
acsc-essential-eight::E8-PATCHAPP-ISM-1808Patch applications (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities
acsc-essential-eight::E8-PATCHAPP-ISM-1876Patch applications (ISM-1876): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHAPP-ISM-1901Patch applications (ISM-1901): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
acsc-essential-eight::E8-PATCHAPP-ISM-1905Patch applications (ISM-1905): Online services that are no longer supported by vendors are removed

Patch operating systems – ACSC Essential Eight

17 controls
Controls in the Patch operating systems – ACSC Essential Eight domain of ACSC Essential Eight — 17 controls
CodeTitle
acsc-essential-eight::E8-PATCHOS-ISM-1407Patch operating systems (ISM-1407): The latest release, or the previous release, of operating systems are used
acsc-essential-eight::E8-PATCHOS-ISM-1501Patch operating systems (ISM-1501): Operating systems that are no longer supported by vendors are replaced
acsc-essential-eight::E8-PATCHOS-ISM-1694Patch operating systems (ISM-1694): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1695Patch operating systems (ISM-1695): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release
acsc-essential-eight::E8-PATCHOS-ISM-1696Patch operating systems (ISM-1696): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1697Patch operating systems (ISM-1697): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1701Patch operating systems (ISM-1701): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices
acsc-essential-eight::E8-PATCHOS-ISM-1702Patch operating systems (ISM-1702): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices
acsc-essential-eight::E8-PATCHOS-ISM-1703Patch operating systems (ISM-1703): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers
acsc-essential-eight::E8-PATCHOS-ISM-1807Patch operating systems (ISM-1807): An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities
acsc-essential-eight::E8-PATCHOS-ISM-1808Patch operating systems (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities
acsc-essential-eight::E8-PATCHOS-ISM-1877Patch operating systems (ISM-1877): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1879Patch operating systems (ISM-1879): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1900Patch operating systems (ISM-1900): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware
acsc-essential-eight::E8-PATCHOS-ISM-1902Patch operating systems (ISM-1902): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1903Patch operating systems (ISM-1903): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist
acsc-essential-eight::E8-PATCHOS-ISM-1904Patch operating systems (ISM-1904): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist

Regular backups – ACSC Essential Eight

11 controls
Controls in the Regular backups – ACSC Essential Eight domain of ACSC Essential Eight — 11 controls
CodeTitle
acsc-essential-eight::E8-BACKUP-ISM-1511Regular backups (ISM-1511): Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements
acsc-essential-eight::E8-BACKUP-ISM-1515Regular backups (ISM-1515): Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises
acsc-essential-eight::E8-BACKUP-ISM-1705Regular backups (ISM-1705): Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts
acsc-essential-eight::E8-BACKUP-ISM-1706Regular backups (ISM-1706): Privileged user accounts (excluding backup administrator accounts) cannot access their own backups
acsc-essential-eight::E8-BACKUP-ISM-1707Regular backups (ISM-1707): Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups
acsc-essential-eight::E8-BACKUP-ISM-1708Regular backups (ISM-1708): Backup administrator accounts are prevented from modifying and deleting backups during their retention period
acsc-essential-eight::E8-BACKUP-ISM-1810Regular backups (ISM-1810): Backups of data, applications and settings are synchronised to enable restoration to a common point in time
acsc-essential-eight::E8-BACKUP-ISM-1811Regular backups (ISM-1811): Backups of data, applications and settings are retained in a secure and resilient manner
acsc-essential-eight::E8-BACKUP-ISM-1812Regular backups (ISM-1812): Unprivileged user accounts cannot access backups belonging to other user accounts
acsc-essential-eight::E8-BACKUP-ISM-1813Regular backups (ISM-1813): Unprivileged user accounts cannot access their own backups
acsc-essential-eight::E8-BACKUP-ISM-1814Regular backups (ISM-1814): Unprivileged user accounts are prevented from modifying and deleting backups

Restrict Microsoft Office macros – ACSC Essential Eight

11 controls
Controls in the Restrict Microsoft Office macros – ACSC Essential Eight domain of ACSC Essential Eight — 11 controls
CodeTitle
acsc-essential-eight::E8-MACRO-ISM-1487Restrict Microsoft Office macros (ISM-1487): Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations
acsc-essential-eight::E8-MACRO-ISM-1488Restrict Microsoft Office macros (ISM-1488): Microsoft Office macros in files originating from the internet are blocked
acsc-essential-eight::E8-MACRO-ISM-1489Restrict Microsoft Office macros (ISM-1489): Microsoft Office macro security settings cannot be changed by users
acsc-essential-eight::E8-MACRO-ISM-1671Restrict Microsoft Office macros (ISM-1671): Microsoft Office macros are disabled for users that do not have a demonstrated business requirement
acsc-essential-eight::E8-MACRO-ISM-1672Restrict Microsoft Office macros (ISM-1672): Microsoft Office macro antivirus scanning is enabled
acsc-essential-eight::E8-MACRO-ISM-1673Restrict Microsoft Office macros (ISM-1673): Microsoft Office macros are blocked from making Win32 API calls
acsc-essential-eight::E8-MACRO-ISM-1674Restrict Microsoft Office macros (ISM-1674): Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute
acsc-essential-eight::E8-MACRO-ISM-1675Restrict Microsoft Office macros (ISM-1675): Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View
acsc-essential-eight::E8-MACRO-ISM-1676Restrict Microsoft Office macros (ISM-1676): Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis
acsc-essential-eight::E8-MACRO-ISM-1890Restrict Microsoft Office macros (ISM-1890): Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations
acsc-essential-eight::E8-MACRO-ISM-1891Restrict Microsoft Office macros (ISM-1891): Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View

Restrict administrative privileges – ACSC Essential Eight

29 controls
Controls in the Restrict administrative privileges – ACSC Essential Eight domain of ACSC Essential Eight — 29 controls
CodeTitle
acsc-essential-eight::E8-ADMIN-ISM-0109Restrict administrative privileges (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-ADMIN-ISM-0123Restrict administrative privileges (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
acsc-essential-eight::E8-ADMIN-ISM-0140Restrict administrative privileges (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
acsc-essential-eight::E8-ADMIN-ISM-0445Restrict administrative privileges (ISM-0445): Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access
acsc-essential-eight::E8-ADMIN-ISM-1175Restrict administrative privileges (ISM-1175): Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services
acsc-essential-eight::E8-ADMIN-ISM-1228Restrict administrative privileges (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents
acsc-essential-eight::E8-ADMIN-ISM-1380Restrict administrative privileges (ISM-1380): Privileged users use separate privileged and unprivileged operating environments
acsc-essential-eight::E8-ADMIN-ISM-1387Restrict administrative privileges (ISM-1387): Administrative activities are conducted through jump servers
acsc-essential-eight::E8-ADMIN-ISM-1507Restrict administrative privileges (ISM-1507): Requests for privileged access to systems, applications and data repositories are validated when first requested
acsc-essential-eight::E8-ADMIN-ISM-1508Restrict administrative privileges (ISM-1508): Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties
acsc-essential-eight::E8-ADMIN-ISM-1509Restrict administrative privileges (ISM-1509): Privileged access events are centrally logged
acsc-essential-eight::E8-ADMIN-ISM-1647Restrict administrative privileges (ISM-1647): Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated
acsc-essential-eight::E8-ADMIN-ISM-1648Restrict administrative privileges (ISM-1648): Privileged access to systems and applications is disabled after 45 days of inactivity
acsc-essential-eight::E8-ADMIN-ISM-1649Restrict administrative privileges (ISM-1649): Just-in-time administration is used for administering systems and applications
acsc-essential-eight::E8-ADMIN-ISM-1650Restrict administrative privileges (ISM-1650): Privileged user account and security group management events are centrally logged
acsc-essential-eight::E8-ADMIN-ISM-1685Restrict administrative privileges (ISM-1685): Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed
acsc-essential-eight::E8-ADMIN-ISM-1686Restrict administrative privileges (ISM-1686): Credential Guard functionality is enabled
acsc-essential-eight::E8-ADMIN-ISM-1687Restrict administrative privileges (ISM-1687): Privileged operating environments are not virtualised within unprivileged operating environments
acsc-essential-eight::E8-ADMIN-ISM-1688Restrict administrative privileges (ISM-1688): Unprivileged user accounts cannot logon to privileged operating environments
acsc-essential-eight::E8-ADMIN-ISM-1689Restrict administrative privileges (ISM-1689): Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments
acsc-essential-eight::E8-ADMIN-ISM-1815Restrict administrative privileges (ISM-1815): Event logs are protected from unauthorised modification and deletion
acsc-essential-eight::E8-ADMIN-ISM-1819Restrict administrative privileges (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
acsc-essential-eight::E8-ADMIN-ISM-1861Restrict administrative privileges (ISM-1861): Local Security Authority protection functionality is enabled
acsc-essential-eight::E8-ADMIN-ISM-1883Restrict administrative privileges (ISM-1883): Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties
acsc-essential-eight::E8-ADMIN-ISM-1896Restrict administrative privileges (ISM-1896): Memory integrity functionality is enabled
acsc-essential-eight::E8-ADMIN-ISM-1897Restrict administrative privileges (ISM-1897): Remote Credential Guard functionality is enabled
acsc-essential-eight::E8-ADMIN-ISM-1898Restrict administrative privileges (ISM-1898): Secure Admin Workstations are used in the performance of administrative activities
acsc-essential-eight::E8-ADMIN-ISM-1906Restrict administrative privileges (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-ADMIN-ISM-1907Restrict administrative privileges (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events

User application hardening – ACSC Essential Eight

27 controls
Controls in the User application hardening – ACSC Essential Eight domain of ACSC Essential Eight — 27 controls
CodeTitle
acsc-essential-eight::E8-UAH-ISM-0109User application hardening (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-UAH-ISM-0123User application hardening (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
acsc-essential-eight::E8-UAH-ISM-0140User application hardening (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered
acsc-essential-eight::E8-UAH-ISM-1228User application hardening (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents
acsc-essential-eight::E8-UAH-ISM-1412User application hardening (ISM-1412): Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur
acsc-essential-eight::E8-UAH-ISM-1485User application hardening (ISM-1485): Web browsers do not process web advertisements from the internet
acsc-essential-eight::E8-UAH-ISM-1486User application hardening (ISM-1486): Web browsers do not process Java from the internet
acsc-essential-eight::E8-UAH-ISM-1542User application hardening (ISM-1542): Microsoft Office is configured to prevent activation of Object Linking and Embedding packages
acsc-essential-eight::E8-UAH-ISM-1585User application hardening (ISM-1585): Web browser security settings cannot be changed by users
acsc-essential-eight::E8-UAH-ISM-1621User application hardening (ISM-1621): Windows PowerShell 2.0 is disabled or removed
acsc-essential-eight::E8-UAH-ISM-1622User application hardening (ISM-1622): PowerShell is configured to use Constrained Language Mode
acsc-essential-eight::E8-UAH-ISM-1623User application hardening (ISM-1623): PowerShell module logging, script block logging and transcription events are centrally logged
acsc-essential-eight::E8-UAH-ISM-1654User application hardening (ISM-1654): Internet Explorer 11 is disabled or removed
acsc-essential-eight::E8-UAH-ISM-1655User application hardening (ISM-1655): .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed
acsc-essential-eight::E8-UAH-ISM-1667User application hardening (ISM-1667): Microsoft Office is blocked from creating child processes
acsc-essential-eight::E8-UAH-ISM-1668User application hardening (ISM-1668): Microsoft Office is blocked from creating executable content
acsc-essential-eight::E8-UAH-ISM-1669User application hardening (ISM-1669): Microsoft Office is blocked from injecting code into other processes
acsc-essential-eight::E8-UAH-ISM-1670User application hardening (ISM-1670): PDF software is blocked from creating child processes
acsc-essential-eight::E8-UAH-ISM-1815User application hardening (ISM-1815): Event logs are protected from unauthorised modification and deletion
acsc-essential-eight::E8-UAH-ISM-1819User application hardening (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted
acsc-essential-eight::E8-UAH-ISM-1823User application hardening (ISM-1823): Office productivity suite security settings cannot be changed by users
acsc-essential-eight::E8-UAH-ISM-1824User application hardening (ISM-1824): PDF software security settings cannot be changed by users
acsc-essential-eight::E8-UAH-ISM-1859User application hardening (ISM-1859): Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur
acsc-essential-eight::E8-UAH-ISM-1860User application hardening (ISM-1860): PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur
acsc-essential-eight::E8-UAH-ISM-1889User application hardening (ISM-1889): Command line process creation events are centrally logged
acsc-essential-eight::E8-UAH-ISM-1906User application hardening (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events
acsc-essential-eight::E8-UAH-ISM-1907User application hardening (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events

Your Compliance Coverage

If you comply with ACSC Essential Eight, you already cover:

Maps to 31 other frameworks

176 total controls
ISO 27002:2022
172 source controls mapped|31 target controls covered
98%
Australian Information Security Manual
167 source controls mapped|126 target controls covered
95%
NIST SP 800-53 Rev 5
24 source controls mapped|36 target controls covered
14%
FedRAMP High
24 source controls mapped|62 target controls covered
14%
FedRAMP Moderate
24 source controls mapped|62 target controls covered
14%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
24 source controls mapped|40 target controls covered
14%
Azure Security Benchmark
24 source controls mapped|39 target controls covered
14%
ASD Strategies to Mitigate Cyber Security Incidents
24 source controls mapped|19 target controls covered
14%
CIS Controls v8
24 source controls mapped|44 target controls covered
14%
CMMC 2.0
22 source controls mapped|39 target controls covered
13%
C5 (Germany)
21 source controls mapped|26 target controls covered
12%
NIST Cybersecurity Framework 2.0
20 source controls mapped|32 target controls covered
11%
ISO 27001:2022
20 source controls mapped|31 target controls covered
11%
NIST SP 800-171 Rev 3
20 source controls mapped|32 target controls covered
11%
SOC 2
19 source controls mapped|17 target controls covered
11%
HIPAA Security Rule
18 source controls mapped|25 target controls covered
10%
NIST SP 800-66 Rev 2
18 source controls mapped|25 target controls covered
10%
NIST SP 800-161 Rev 1
18 source controls mapped|17 target controls covered
10%
PCI DSS 4.0
18 source controls mapped|37 target controls covered
10%
NIST SP 800-171
15 source controls mapped|4 target controls covered
9%
AWS Well-Architected Security Pillar
14 source controls mapped|21 target controls covered
8%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
14 source controls mapped|20 target controls covered
8%
SWIFT CSCF
9 source controls mapped|3 target controls covered
5%
ASIC Cyber Resilience Good Practices
8 source controls mapped|1 target controls covered
5%
Defence Industry Security Program (DISP)
8 source controls mapped|1 target controls covered
5%
Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
7 source controls mapped|1 target controls covered
4%
Australia Consumer Data Right - Banking (CDR)
5 source controls mapped|3 target controls covered
3%
SQF Code Edition 9 - Safe Quality Food
3 source controls mapped|1 target controls covered
2%
Australian Energy Sector Cyber Security Framework (AESCSF)
3 source controls mapped|2 target controls covered
2%
ISO 22301:2019
2 source controls mapped|6 target controls covered
1%
ATO Digital Service Provider (DSP) Operational Security Framework
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what ACSC Essential Eight overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is ACSC Essential Eight and who does it apply to?

ACSC Essential Eight is a compliance framework from Australia with 8 domains and 152 controls. ASD's Essential Eight Maturity Model (November 2023): the eight mitigation strategies at Maturity Levels One to Three, each requirement as ASD states it with its ISM control and the levels it applies at, including the requirements that unsupported applications, online services and operating systems are removed or replaced. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ACSC Essential Eight actually require?

ACSC Essential Eight has 152 controls organised across 8 domains. The largest domains are Restrict administrative privileges – ACSC Essential Eight (29 controls), User application hardening – ACSC Essential Eight (27 controls), Multi-factor authentication – ACSC Essential Eight (24 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ACSC Essential Eight do I already cover?

ACSC Essential Eight maps to 31 other compliance frameworks. The top mapping partners are ISO 27002:2022 (98% coverage), Australian Information Security Manual (95% coverage), NIST SP 800-53 Rev 5 (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ACSC Essential Eight?

Start your ACSC Essential Eight compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ACSC Essential Eight requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 152 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required