What Essential Eight means in practice
The Essential Eight is the framework most Australian boards, insurers and government buyers reference when they ask whether an organisation is secure. It was published by the Australian Signals Directorate as a prioritised subset of a much longer list of mitigation strategies, chosen because these eight prevent or limit the majority of intrusions the ASD actually sees.
The eight strategies fall into three groups. Preventing attacks covers application control, patching applications, configuring Microsoft Office macro settings and user application hardening. Limiting the extent of an incident covers restricting administrative privileges, patching operating systems and multi-factor authentication. Recovering data covers regular backups, tested and held where an attacker with domain access cannot destroy them.
Maturity is measured on a scale from Maturity Level Zero, meaning the strategy is not implemented in any meaningful way, through Maturity Level Three, which assumes an adversary willing to invest time and effort in a specific target. Most mid-sized Australian organisations are asked to demonstrate Maturity Level One or Two. Non-corporate Commonwealth entities operate under mandatory requirements; for private businesses the framework is influential rather than legally binding, but it increasingly appears in insurance questionnaires, tender responses and supply chain assessments.
In a Microsoft environment, most of the Essential Eight maps directly onto configuration you already own. Multi-factor authentication and administrative privilege restriction are Microsoft Entra ID work, including conditional access and privileged role management. Patching applications and operating systems is Intune and Windows Update for Business. Macro settings and user application hardening are Intune configuration profiles and Defender attack surface reduction rules. Application control is the hardest of the eight for most organisations and usually the last one attempted.
The practical difficulty is rarely technical. It is evidence: proving a control was in force on a given date, across every device, to somebody who was not there. Designing for exportable evidence from the start is what turns an Essential Eight programme into something that survives an audit.
How we help with this
Related terms
- ISO 27001ISO/IEC 27001 is the international standard for information security management systems.
- Zero TrustZero Trust is a security model that assumes no user, device or network location is inherently trustworthy.
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
