Skip to content

Evidence request lists

ASD Strategies to Mitigate Cyber Security Incidents

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Detecting Cyber Security Incidents and Responding

ASD37-28
Continuous incident detection and response (Excellent)

Continuous incident detection and response with a 24/7 cyber security operations capability for automated and manual analysis of security events.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Continuous incident detection and response
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-29
Host-based IDS/IPS (Very Good)

Host-based intrusion detection/prevention system to identify anomalous behaviour and known malicious activity.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Host-based IDS/IPS
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-30
Endpoint detection and response (Very Good)

Endpoint detection and response software on all computers for centralised analysis and reporting of threat indicators.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Endpoint detection and response
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-31
Hunt to discover incidents (Very Good)

Hunt to discover cyber security incidents based on knowledge of adversary tradecraft and analysis of logs, events and other data sources.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Hunt to discover incidents
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-32
Network-based IDS/IPS (Limited)

Network-based intrusion detection/prevention system using signatures and heuristics to identify anomalous traffic.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Network-based IDS/IPS
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-33
Capture network traffic (Limited)

Capture network traffic to and from corporate computers and store for at least several days to support the detection of cyber security incidents.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Capture network traffic
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met

Limiting the Extent of Cyber Security Incidents

ASD37-18
Restrict administrative privileges (Essential)

Restrict administrative privileges to operating systems and applications based on user duties. Regularly revalidate the need for privileges. Don't use privileged accounts for reading email and web browsing.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Restrict administrative privileges
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-19
Patch operating systems (Essential)

Patch/mitigate computers (including network devices) with extreme risk vulnerabilities within 48 hours. Use the latest version of operating systems. Don't use unsupported versions.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Patch operating systems
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-20
Multi-factor authentication (Essential)

Multi-factor authentication including for VPNs, RDP, SSH and other remote access, and for all users when they perform a privileged action or access an important (sensitive/high-availability) data repository.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Multi-factor authentication
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-21
Disable local administrator accounts (Excellent)

Disable local administrator accounts or assign unique, complex, unpredictable passphrases to each, using a tool such as Microsoft LAPS.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Disable local administrator accounts
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-22
Network segmentation (Excellent)

Network segmentation and segregation to limit the impact of an intrusion. Deny traffic between computers unless required.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Network segmentation
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-23
Protect authentication credentials (Excellent)

Protect authentication credentials by removing them from memory when no longer needed. Use credential caching only when required. Centralise credential storage.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Protect authentication credentials
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-24
Non-persistent virtualised sandboxed environment (Very Good)

Non-persistent virtualised sandboxed environment for risky activities such as processing untrusted documents and web browsing.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Non-persistent virtualised sandboxed environment
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-25
Software firewall - inbound (Very Good)

Software-based application firewall, blocking incoming network traffic that is malicious or unauthorised.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Software firewall - inbound
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-26
Software firewall - outbound (Very Good)

Software-based application firewall, blocking outgoing network traffic that is not generated by approved/legitimate programs.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Software firewall - outbound
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-27
Outbound data loss prevention (Very Good)

Outbound web and email data loss prevention to detect and block large or unusual volumes of data or sensitive data being transferred.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Outbound data loss prevention
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met

Preventing Malicious Insiders

ASD37-37
Personnel management (Very Good)

Personnel management including pre-employment checks, ongoing security awareness training, and management of disgruntled employees and departing personnel.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Personnel management
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met

Preventing Malware Delivery and Execution

ASD37-01
Application control (Essential)

Application control to prevent execution of unapproved/malicious programs including .exe, DLL, scripts and installers.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Application control
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-02
Patch applications (Essential)

Patch/mitigate computers with extreme risk vulnerabilities within 48 hours. Use the latest version of applications.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Patch applications
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-03
Configure Microsoft Office macro settings (Essential)

Configure Microsoft Office macro settings to block macros from the internet, and only allow vetted macros either in Trusted Locations with limited write access or digitally signed with a trusted certificate.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Configure Microsoft Office macro settings
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-04
User application hardening (Essential)

Configure web browsers to block Flash, ads and Java on the internet. Disable unneeded features in Microsoft Office, web browsers and PDF viewers.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: User application hardening
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-05
Automated dynamic analysis of email and web content (Excellent)

Automated dynamic analysis to detonate and analyse content run in a sandbox, e.g. by an email gateway or web proxy. Enrich analysis using reputation and other internet-sourced data.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Automated dynamic analysis of email and web content
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-06
Email content filtering (Excellent)

Filter emails and their content. Only allow approved attachment types. Inspect content for malware. Analyse links.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Email content filtering
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-07
Web content filtering (Excellent)

Filter incoming and outgoing web traffic. Allow only approved types of web content. Inspect incoming web content for malware.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Web content filtering
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-08
Deny direct internet connectivity (Excellent)

Deny corporate computers direct internet connectivity. Web and email traffic should transit through a content-checking proxy server.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Deny direct internet connectivity
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-09
OS generic exploit mitigation (Excellent)

Operating system generic exploit mitigation e.g. Data Execution Prevention (DEP), Address Space Layout Randomisation (ASLR) and Enhanced Mitigation Experience Toolkit (EMET).

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: OS generic exploit mitigation
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-10
Server application hardening (Very Good)

Harden server applications (e.g. web, email, collaboration, database) including removing unneeded features, applying vendor hardening guidance and disabling legacy protocols.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Server application hardening
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-11
Operating system hardening (Very Good)

Harden operating systems based on vendor guidance and ASD guidance. Remove unneeded software, services and ports.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Operating system hardening
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-12
Antivirus software with heuristics (Very Good)

Antivirus software using heuristics and reputation ratings to check a file's prevalence and digital signature prior to execution.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Antivirus software with heuristics
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-13
Control removable storage media (Very Good)

Control removable storage media and connected devices. Block USB storage devices. Disable AutoRun/AutoPlay.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Control removable storage media
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-14
Block spoofed emails (Very Good)

Block spoofed emails. Use Sender Policy Framework (SPF) or Sender ID to check incoming emails. Use DKIM and DMARC for outgoing emails.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Block spoofed emails
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-15
User education (Limited)

User education regarding applicable threats, reporting of suspicious emails, websites and activity, and the consequences of poor security practices.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: User education
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-16
Antivirus software with signatures (Limited)

Antivirus software with up-to-date signatures to identify known malware.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Antivirus software with signatures
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-17
TLS encryption between email servers (Limited)

TLS encryption between email servers to protect the confidentiality of emails in transit between organisations.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: TLS encryption between email servers
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met

Recovering Data and System Availability

ASD37-34
Regular backups (Essential)

Regular backups of important new/changed data, software and configuration settings, stored disconnected, retained for at least three months. Test restoration initially, annually and when IT infrastructure changes.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Regular backups
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-35
Business continuity and disaster recovery plans (Very Good)

Business continuity and disaster recovery plans which are tested, including for the scenario of a complete loss of computing capabilities.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: Business continuity and disaster recovery plans
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
ASD37-36
System recovery capabilities (Very Good)

System recovery capabilities including standard operating environment images to restore computers to a known good state.

Artefacts an auditor will ask for
  • Evidence the mitigation strategy is implemented and maintained: System recovery capabilities
  • Configuration / tooling output demonstrating the strategy
  • Coverage across in-scope systems
  • Records showing ongoing operation
Where this commonly fails
  • Strategy partially deployed (not all systems)
  • No evidence of ongoing maintenance
  • Effectiveness rating not met
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASD Strategies to Mitigate Cyber Security Incidents framework page.