ACSC Essential Eight
ASD's Essential Eight Maturity Model (November 2023): the eight mitigation strategies at Maturity Levels One to Three, each requirement as ASD states it with its ISM control and the levels it applies at, including the requirements that unsupported applications, online services and operating systems are removed or replaced.
ACSC Essential Eight is a compliance framework from Australia with 8 domains and 152 controls that map to 31 other frameworks. The largest domains are Restrict administrative privileges – ACSC Essential Eight (29 controls), User application hardening – ACSC Essential Eight (27 controls), Multi-factor authentication – ACSC Essential Eight (24 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Application control – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-APP-ISM-0109 | Application control (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-APP-ISM-0123 | Application control (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-APP-ISM-0140 | Application control (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-APP-ISM-0843 | Application control (ISM-0843): Application control is implemented on workstations |
| acsc-essential-eight::E8-APP-ISM-1228 | Application control (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents |
| acsc-essential-eight::E8-APP-ISM-1490 | Application control (ISM-1490): Application control is implemented on internet-facing servers |
| acsc-essential-eight::E8-APP-ISM-1544 | Application control (ISM-1544): Microsoft’s recommended application blocklist is implemented |
| acsc-essential-eight::E8-APP-ISM-1582 | Application control (ISM-1582): Application control rulesets are validated on an annual or more frequent basis |
| acsc-essential-eight::E8-APP-ISM-1656 | Application control (ISM-1656): Application control is implemented on non-internet-facing servers |
| acsc-essential-eight::E8-APP-ISM-1657 | Application control (ISM-1657): Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set |
| acsc-essential-eight::E8-APP-ISM-1658 | Application control (ISM-1658): Application control restricts the execution of drivers to an organisation-approved set |
| acsc-essential-eight::E8-APP-ISM-1659 | Application control (ISM-1659): Microsoft’s vulnerable driver blocklist is implemented |
| acsc-essential-eight::E8-APP-ISM-1660 | Application control (ISM-1660): Allowed and blocked application control events are centrally logged |
| acsc-essential-eight::E8-APP-ISM-1815 | Application control (ISM-1815): Event logs are protected from unauthorised modification and deletion |
| acsc-essential-eight::E8-APP-ISM-1819 | Application control (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted |
| acsc-essential-eight::E8-APP-ISM-1870 | Application control (ISM-1870): Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients |
| acsc-essential-eight::E8-APP-ISM-1871 | Application control (ISM-1871): Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients |
| acsc-essential-eight::E8-APP-ISM-1906 | Application control (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-APP-ISM-1907 | Application control (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events |
Multi-factor authentication – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-MFA-ISM-0109 | Multi-factor authentication (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-MFA-ISM-0123 | Multi-factor authentication (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-MFA-ISM-0140 | Multi-factor authentication (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-MFA-ISM-0974 | Multi-factor authentication (ISM-0974): Multi-factor authentication is used to authenticate unprivileged users of systems |
| acsc-essential-eight::E8-MFA-ISM-1173 | Multi-factor authentication (ISM-1173): Multi-factor authentication is used to authenticate privileged users of systems |
| acsc-essential-eight::E8-MFA-ISM-1228 | Multi-factor authentication (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents |
| acsc-essential-eight::E8-MFA-ISM-1401 | Multi-factor authentication (ISM-1401): Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are |
| acsc-essential-eight::E8-MFA-ISM-1504 | Multi-factor authentication (ISM-1504): Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data |
| acsc-essential-eight::E8-MFA-ISM-1505 | Multi-factor authentication (ISM-1505): Multi-factor authentication is used to authenticate users of data repositories |
| acsc-essential-eight::E8-MFA-ISM-1679 | Multi-factor authentication (ISM-1679): Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data |
| acsc-essential-eight::E8-MFA-ISM-1680 | Multi-factor authentication (ISM-1680): Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data |
| acsc-essential-eight::E8-MFA-ISM-1681 | Multi-factor authentication (ISM-1681): Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data |
| acsc-essential-eight::E8-MFA-ISM-1682 | Multi-factor authentication (ISM-1682): Multi-factor authentication used for authenticating users of systems is phishing-resistant |
| acsc-essential-eight::E8-MFA-ISM-1683 | Multi-factor authentication (ISM-1683): Successful and unsuccessful multi-factor authentication events are centrally logged |
| acsc-essential-eight::E8-MFA-ISM-1815 | Multi-factor authentication (ISM-1815): Event logs are protected from unauthorised modification and deletion |
| acsc-essential-eight::E8-MFA-ISM-1819 | Multi-factor authentication (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted |
| acsc-essential-eight::E8-MFA-ISM-1872 | Multi-factor authentication (ISM-1872): Multi-factor authentication used for authenticating users of online services is phishing-resistant |
| acsc-essential-eight::E8-MFA-ISM-1873 | Multi-factor authentication (ISM-1873): Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option |
| acsc-essential-eight::E8-MFA-ISM-1874 | Multi-factor authentication (ISM-1874): Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant |
| acsc-essential-eight::E8-MFA-ISM-1892 | Multi-factor authentication (ISM-1892): Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data |
| acsc-essential-eight::E8-MFA-ISM-1893 | Multi-factor authentication (ISM-1893): Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data |
| acsc-essential-eight::E8-MFA-ISM-1894 | Multi-factor authentication (ISM-1894): Multi-factor authentication used for authenticating users of data repositories is phishing-resistant |
| acsc-essential-eight::E8-MFA-ISM-1906 | Multi-factor authentication (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-MFA-ISM-1907 | Multi-factor authentication (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events |
Patch applications – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-PATCHAPP-ISM-0304 | Patch applications (ISM-0304): Applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed |
| acsc-essential-eight::E8-PATCHAPP-ISM-1690 | Patch applications (ISM-1690): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
| acsc-essential-eight::E8-PATCHAPP-ISM-1691 | Patch applications (ISM-1691): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release |
| acsc-essential-eight::E8-PATCHAPP-ISM-1692 | Patch applications (ISM-1692): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHAPP-ISM-1693 | Patch applications (ISM-1693): Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release |
| acsc-essential-eight::E8-PATCHAPP-ISM-1698 | Patch applications (ISM-1698): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services |
| acsc-essential-eight::E8-PATCHAPP-ISM-1699 | Patch applications (ISM-1699): A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products |
| acsc-essential-eight::E8-PATCHAPP-ISM-1700 | Patch applications (ISM-1700): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products |
| acsc-essential-eight::E8-PATCHAPP-ISM-1704 | Patch applications (ISM-1704): Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed |
| acsc-essential-eight::E8-PATCHAPP-ISM-1807 | Patch applications (ISM-1807): An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities |
| acsc-essential-eight::E8-PATCHAPP-ISM-1808 | Patch applications (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities |
| acsc-essential-eight::E8-PATCHAPP-ISM-1876 | Patch applications (ISM-1876): Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHAPP-ISM-1901 | Patch applications (ISM-1901): Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
| acsc-essential-eight::E8-PATCHAPP-ISM-1905 | Patch applications (ISM-1905): Online services that are no longer supported by vendors are removed |
Patch operating systems – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-PATCHOS-ISM-1407 | Patch operating systems (ISM-1407): The latest release, or the previous release, of operating systems are used |
| acsc-essential-eight::E8-PATCHOS-ISM-1501 | Patch operating systems (ISM-1501): Operating systems that are no longer supported by vendors are replaced |
| acsc-essential-eight::E8-PATCHOS-ISM-1694 | Patch operating systems (ISM-1694): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1695 | Patch operating systems (ISM-1695): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release |
| acsc-essential-eight::E8-PATCHOS-ISM-1696 | Patch operating systems (ISM-1696): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1697 | Patch operating systems (ISM-1697): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1701 | Patch operating systems (ISM-1701): A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices |
| acsc-essential-eight::E8-PATCHOS-ISM-1702 | Patch operating systems (ISM-1702): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices |
| acsc-essential-eight::E8-PATCHOS-ISM-1703 | Patch operating systems (ISM-1703): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers |
| acsc-essential-eight::E8-PATCHOS-ISM-1807 | Patch operating systems (ISM-1807): An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities |
| acsc-essential-eight::E8-PATCHOS-ISM-1808 | Patch operating systems (ISM-1808): A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities |
| acsc-essential-eight::E8-PATCHOS-ISM-1877 | Patch operating systems (ISM-1877): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1879 | Patch operating systems (ISM-1879): Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1900 | Patch operating systems (ISM-1900): A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware |
| acsc-essential-eight::E8-PATCHOS-ISM-1902 | Patch operating systems (ISM-1902): Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1903 | Patch operating systems (ISM-1903): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist |
| acsc-essential-eight::E8-PATCHOS-ISM-1904 | Patch operating systems (ISM-1904): Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist |
Regular backups – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-BACKUP-ISM-1511 | Regular backups (ISM-1511): Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements |
| acsc-essential-eight::E8-BACKUP-ISM-1515 | Regular backups (ISM-1515): Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises |
| acsc-essential-eight::E8-BACKUP-ISM-1705 | Regular backups (ISM-1705): Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts |
| acsc-essential-eight::E8-BACKUP-ISM-1706 | Regular backups (ISM-1706): Privileged user accounts (excluding backup administrator accounts) cannot access their own backups |
| acsc-essential-eight::E8-BACKUP-ISM-1707 | Regular backups (ISM-1707): Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups |
| acsc-essential-eight::E8-BACKUP-ISM-1708 | Regular backups (ISM-1708): Backup administrator accounts are prevented from modifying and deleting backups during their retention period |
| acsc-essential-eight::E8-BACKUP-ISM-1810 | Regular backups (ISM-1810): Backups of data, applications and settings are synchronised to enable restoration to a common point in time |
| acsc-essential-eight::E8-BACKUP-ISM-1811 | Regular backups (ISM-1811): Backups of data, applications and settings are retained in a secure and resilient manner |
| acsc-essential-eight::E8-BACKUP-ISM-1812 | Regular backups (ISM-1812): Unprivileged user accounts cannot access backups belonging to other user accounts |
| acsc-essential-eight::E8-BACKUP-ISM-1813 | Regular backups (ISM-1813): Unprivileged user accounts cannot access their own backups |
| acsc-essential-eight::E8-BACKUP-ISM-1814 | Regular backups (ISM-1814): Unprivileged user accounts are prevented from modifying and deleting backups |
Restrict Microsoft Office macros – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-MACRO-ISM-1487 | Restrict Microsoft Office macros (ISM-1487): Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations |
| acsc-essential-eight::E8-MACRO-ISM-1488 | Restrict Microsoft Office macros (ISM-1488): Microsoft Office macros in files originating from the internet are blocked |
| acsc-essential-eight::E8-MACRO-ISM-1489 | Restrict Microsoft Office macros (ISM-1489): Microsoft Office macro security settings cannot be changed by users |
| acsc-essential-eight::E8-MACRO-ISM-1671 | Restrict Microsoft Office macros (ISM-1671): Microsoft Office macros are disabled for users that do not have a demonstrated business requirement |
| acsc-essential-eight::E8-MACRO-ISM-1672 | Restrict Microsoft Office macros (ISM-1672): Microsoft Office macro antivirus scanning is enabled |
| acsc-essential-eight::E8-MACRO-ISM-1673 | Restrict Microsoft Office macros (ISM-1673): Microsoft Office macros are blocked from making Win32 API calls |
| acsc-essential-eight::E8-MACRO-ISM-1674 | Restrict Microsoft Office macros (ISM-1674): Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute |
| acsc-essential-eight::E8-MACRO-ISM-1675 | Restrict Microsoft Office macros (ISM-1675): Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View |
| acsc-essential-eight::E8-MACRO-ISM-1676 | Restrict Microsoft Office macros (ISM-1676): Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis |
| acsc-essential-eight::E8-MACRO-ISM-1890 | Restrict Microsoft Office macros (ISM-1890): Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations |
| acsc-essential-eight::E8-MACRO-ISM-1891 | Restrict Microsoft Office macros (ISM-1891): Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View |
Restrict administrative privileges – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-ADMIN-ISM-0109 | Restrict administrative privileges (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-ADMIN-ISM-0123 | Restrict administrative privileges (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-ADMIN-ISM-0140 | Restrict administrative privileges (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-ADMIN-ISM-0445 | Restrict administrative privileges (ISM-0445): Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access |
| acsc-essential-eight::E8-ADMIN-ISM-1175 | Restrict administrative privileges (ISM-1175): Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services |
| acsc-essential-eight::E8-ADMIN-ISM-1228 | Restrict administrative privileges (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents |
| acsc-essential-eight::E8-ADMIN-ISM-1380 | Restrict administrative privileges (ISM-1380): Privileged users use separate privileged and unprivileged operating environments |
| acsc-essential-eight::E8-ADMIN-ISM-1387 | Restrict administrative privileges (ISM-1387): Administrative activities are conducted through jump servers |
| acsc-essential-eight::E8-ADMIN-ISM-1507 | Restrict administrative privileges (ISM-1507): Requests for privileged access to systems, applications and data repositories are validated when first requested |
| acsc-essential-eight::E8-ADMIN-ISM-1508 | Restrict administrative privileges (ISM-1508): Privileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their duties |
| acsc-essential-eight::E8-ADMIN-ISM-1509 | Restrict administrative privileges (ISM-1509): Privileged access events are centrally logged |
| acsc-essential-eight::E8-ADMIN-ISM-1647 | Restrict administrative privileges (ISM-1647): Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated |
| acsc-essential-eight::E8-ADMIN-ISM-1648 | Restrict administrative privileges (ISM-1648): Privileged access to systems and applications is disabled after 45 days of inactivity |
| acsc-essential-eight::E8-ADMIN-ISM-1649 | Restrict administrative privileges (ISM-1649): Just-in-time administration is used for administering systems and applications |
| acsc-essential-eight::E8-ADMIN-ISM-1650 | Restrict administrative privileges (ISM-1650): Privileged user account and security group management events are centrally logged |
| acsc-essential-eight::E8-ADMIN-ISM-1685 | Restrict administrative privileges (ISM-1685): Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed |
| acsc-essential-eight::E8-ADMIN-ISM-1686 | Restrict administrative privileges (ISM-1686): Credential Guard functionality is enabled |
| acsc-essential-eight::E8-ADMIN-ISM-1687 | Restrict administrative privileges (ISM-1687): Privileged operating environments are not virtualised within unprivileged operating environments |
| acsc-essential-eight::E8-ADMIN-ISM-1688 | Restrict administrative privileges (ISM-1688): Unprivileged user accounts cannot logon to privileged operating environments |
| acsc-essential-eight::E8-ADMIN-ISM-1689 | Restrict administrative privileges (ISM-1689): Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments |
| acsc-essential-eight::E8-ADMIN-ISM-1815 | Restrict administrative privileges (ISM-1815): Event logs are protected from unauthorised modification and deletion |
| acsc-essential-eight::E8-ADMIN-ISM-1819 | Restrict administrative privileges (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted |
| acsc-essential-eight::E8-ADMIN-ISM-1861 | Restrict administrative privileges (ISM-1861): Local Security Authority protection functionality is enabled |
| acsc-essential-eight::E8-ADMIN-ISM-1883 | Restrict administrative privileges (ISM-1883): Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties |
| acsc-essential-eight::E8-ADMIN-ISM-1896 | Restrict administrative privileges (ISM-1896): Memory integrity functionality is enabled |
| acsc-essential-eight::E8-ADMIN-ISM-1897 | Restrict administrative privileges (ISM-1897): Remote Credential Guard functionality is enabled |
| acsc-essential-eight::E8-ADMIN-ISM-1898 | Restrict administrative privileges (ISM-1898): Secure Admin Workstations are used in the performance of administrative activities |
| acsc-essential-eight::E8-ADMIN-ISM-1906 | Restrict administrative privileges (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-ADMIN-ISM-1907 | Restrict administrative privileges (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events |
User application hardening – ACSC Essential Eight
| Code | Title |
|---|---|
| acsc-essential-eight::E8-UAH-ISM-0109 | User application hardening (ISM-0109): Event logs from workstations are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-UAH-ISM-0123 | User application hardening (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-UAH-ISM-0140 | User application hardening (ISM-0140): Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered |
| acsc-essential-eight::E8-UAH-ISM-1228 | User application hardening (ISM-1228): Cyber security events are analysed in a timely manner to identify cyber security incidents |
| acsc-essential-eight::E8-UAH-ISM-1412 | User application hardening (ISM-1412): Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur |
| acsc-essential-eight::E8-UAH-ISM-1485 | User application hardening (ISM-1485): Web browsers do not process web advertisements from the internet |
| acsc-essential-eight::E8-UAH-ISM-1486 | User application hardening (ISM-1486): Web browsers do not process Java from the internet |
| acsc-essential-eight::E8-UAH-ISM-1542 | User application hardening (ISM-1542): Microsoft Office is configured to prevent activation of Object Linking and Embedding packages |
| acsc-essential-eight::E8-UAH-ISM-1585 | User application hardening (ISM-1585): Web browser security settings cannot be changed by users |
| acsc-essential-eight::E8-UAH-ISM-1621 | User application hardening (ISM-1621): Windows PowerShell 2.0 is disabled or removed |
| acsc-essential-eight::E8-UAH-ISM-1622 | User application hardening (ISM-1622): PowerShell is configured to use Constrained Language Mode |
| acsc-essential-eight::E8-UAH-ISM-1623 | User application hardening (ISM-1623): PowerShell module logging, script block logging and transcription events are centrally logged |
| acsc-essential-eight::E8-UAH-ISM-1654 | User application hardening (ISM-1654): Internet Explorer 11 is disabled or removed |
| acsc-essential-eight::E8-UAH-ISM-1655 | User application hardening (ISM-1655): .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed |
| acsc-essential-eight::E8-UAH-ISM-1667 | User application hardening (ISM-1667): Microsoft Office is blocked from creating child processes |
| acsc-essential-eight::E8-UAH-ISM-1668 | User application hardening (ISM-1668): Microsoft Office is blocked from creating executable content |
| acsc-essential-eight::E8-UAH-ISM-1669 | User application hardening (ISM-1669): Microsoft Office is blocked from injecting code into other processes |
| acsc-essential-eight::E8-UAH-ISM-1670 | User application hardening (ISM-1670): PDF software is blocked from creating child processes |
| acsc-essential-eight::E8-UAH-ISM-1815 | User application hardening (ISM-1815): Event logs are protected from unauthorised modification and deletion |
| acsc-essential-eight::E8-UAH-ISM-1819 | User application hardening (ISM-1819): Following the identification of a cyber security incident, the cyber security incident response plan is enacted |
| acsc-essential-eight::E8-UAH-ISM-1823 | User application hardening (ISM-1823): Office productivity suite security settings cannot be changed by users |
| acsc-essential-eight::E8-UAH-ISM-1824 | User application hardening (ISM-1824): PDF software security settings cannot be changed by users |
| acsc-essential-eight::E8-UAH-ISM-1859 | User application hardening (ISM-1859): Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur |
| acsc-essential-eight::E8-UAH-ISM-1860 | User application hardening (ISM-1860): PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur |
| acsc-essential-eight::E8-UAH-ISM-1889 | User application hardening (ISM-1889): Command line process creation events are centrally logged |
| acsc-essential-eight::E8-UAH-ISM-1906 | User application hardening (ISM-1906): Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events |
| acsc-essential-eight::E8-UAH-ISM-1907 | User application hardening (ISM-1907): Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events |
Your Compliance Coverage
If you comply with ACSC Essential Eight, you already cover:
ISO 27002:2022
98%
172 controls mapped
Compare →Australian Information Security Manual
95%
167 controls mapped
Compare →NIST SP 800-53 Rev 5
14%
24 controls mapped
Compare →+ 28 more: FedRAMP High (14%), FedRAMP Moderate (14%)
See all 31 mapped frameworks ↓Maps to 31 other frameworks
Coverage is not the same as your position
This page shows what ACSC Essential Eight overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ACSC Essential Eight and who does it apply to?
ACSC Essential Eight is a compliance framework from Australia with 8 domains and 152 controls. ASD's Essential Eight Maturity Model (November 2023): the eight mitigation strategies at Maturity Levels One to Three, each requirement as ASD states it with its ISM control and the levels it applies at, including the requirements that unsupported applications, online services and operating systems are removed or replaced. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ACSC Essential Eight actually require?
ACSC Essential Eight has 152 controls organised across 8 domains. The largest domains are Restrict administrative privileges – ACSC Essential Eight (29 controls), User application hardening – ACSC Essential Eight (27 controls), Multi-factor authentication – ACSC Essential Eight (24 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ACSC Essential Eight do I already cover?
ACSC Essential Eight maps to 31 other compliance frameworks. The top mapping partners are ISO 27002:2022 (98% coverage), Australian Information Security Manual (95% coverage), NIST SP 800-53 Rev 5 (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ACSC Essential Eight?
Start your ACSC Essential Eight compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ACSC Essential Eight requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 152 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required