ASD Strategies to Mitigate Cyber Security Incidents
Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Detecting Cyber Security Incidents and Responding
Continuous incident detection and response with a 24/7 cyber security operations capability for automated and manual analysis of security events.
- Evidence the mitigation strategy is implemented and maintained: Continuous incident detection and response
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Host-based intrusion detection/prevention system to identify anomalous behaviour and known malicious activity.
- Evidence the mitigation strategy is implemented and maintained: Host-based IDS/IPS
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Endpoint detection and response software on all computers for centralised analysis and reporting of threat indicators.
- Evidence the mitigation strategy is implemented and maintained: Endpoint detection and response
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Hunt to discover cyber security incidents based on knowledge of adversary tradecraft and analysis of logs, events and other data sources.
- Evidence the mitigation strategy is implemented and maintained: Hunt to discover incidents
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Network-based intrusion detection/prevention system using signatures and heuristics to identify anomalous traffic.
- Evidence the mitigation strategy is implemented and maintained: Network-based IDS/IPS
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Capture network traffic to and from corporate computers and store for at least several days to support the detection of cyber security incidents.
- Evidence the mitigation strategy is implemented and maintained: Capture network traffic
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Limiting the Extent of Cyber Security Incidents
Restrict administrative privileges to operating systems and applications based on user duties. Regularly revalidate the need for privileges. Don't use privileged accounts for reading email and web browsing.
- Evidence the mitigation strategy is implemented and maintained: Restrict administrative privileges
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Patch/mitigate computers (including network devices) with extreme risk vulnerabilities within 48 hours. Use the latest version of operating systems. Don't use unsupported versions.
- Evidence the mitigation strategy is implemented and maintained: Patch operating systems
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Multi-factor authentication including for VPNs, RDP, SSH and other remote access, and for all users when they perform a privileged action or access an important (sensitive/high-availability) data repository.
- Evidence the mitigation strategy is implemented and maintained: Multi-factor authentication
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Disable local administrator accounts or assign unique, complex, unpredictable passphrases to each, using a tool such as Microsoft LAPS.
- Evidence the mitigation strategy is implemented and maintained: Disable local administrator accounts
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Network segmentation and segregation to limit the impact of an intrusion. Deny traffic between computers unless required.
- Evidence the mitigation strategy is implemented and maintained: Network segmentation
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Protect authentication credentials by removing them from memory when no longer needed. Use credential caching only when required. Centralise credential storage.
- Evidence the mitigation strategy is implemented and maintained: Protect authentication credentials
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Non-persistent virtualised sandboxed environment for risky activities such as processing untrusted documents and web browsing.
- Evidence the mitigation strategy is implemented and maintained: Non-persistent virtualised sandboxed environment
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Software-based application firewall, blocking incoming network traffic that is malicious or unauthorised.
- Evidence the mitigation strategy is implemented and maintained: Software firewall - inbound
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Software-based application firewall, blocking outgoing network traffic that is not generated by approved/legitimate programs.
- Evidence the mitigation strategy is implemented and maintained: Software firewall - outbound
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Outbound web and email data loss prevention to detect and block large or unusual volumes of data or sensitive data being transferred.
- Evidence the mitigation strategy is implemented and maintained: Outbound data loss prevention
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Preventing Malicious Insiders
Personnel management including pre-employment checks, ongoing security awareness training, and management of disgruntled employees and departing personnel.
- Evidence the mitigation strategy is implemented and maintained: Personnel management
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Preventing Malware Delivery and Execution
Application control to prevent execution of unapproved/malicious programs including .exe, DLL, scripts and installers.
- Evidence the mitigation strategy is implemented and maintained: Application control
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Patch/mitigate computers with extreme risk vulnerabilities within 48 hours. Use the latest version of applications.
- Evidence the mitigation strategy is implemented and maintained: Patch applications
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Configure Microsoft Office macro settings to block macros from the internet, and only allow vetted macros either in Trusted Locations with limited write access or digitally signed with a trusted certificate.
- Evidence the mitigation strategy is implemented and maintained: Configure Microsoft Office macro settings
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Configure web browsers to block Flash, ads and Java on the internet. Disable unneeded features in Microsoft Office, web browsers and PDF viewers.
- Evidence the mitigation strategy is implemented and maintained: User application hardening
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Automated dynamic analysis to detonate and analyse content run in a sandbox, e.g. by an email gateway or web proxy. Enrich analysis using reputation and other internet-sourced data.
- Evidence the mitigation strategy is implemented and maintained: Automated dynamic analysis of email and web content
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Filter emails and their content. Only allow approved attachment types. Inspect content for malware. Analyse links.
- Evidence the mitigation strategy is implemented and maintained: Email content filtering
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Filter incoming and outgoing web traffic. Allow only approved types of web content. Inspect incoming web content for malware.
- Evidence the mitigation strategy is implemented and maintained: Web content filtering
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Deny corporate computers direct internet connectivity. Web and email traffic should transit through a content-checking proxy server.
- Evidence the mitigation strategy is implemented and maintained: Deny direct internet connectivity
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Operating system generic exploit mitigation e.g. Data Execution Prevention (DEP), Address Space Layout Randomisation (ASLR) and Enhanced Mitigation Experience Toolkit (EMET).
- Evidence the mitigation strategy is implemented and maintained: OS generic exploit mitigation
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Harden server applications (e.g. web, email, collaboration, database) including removing unneeded features, applying vendor hardening guidance and disabling legacy protocols.
- Evidence the mitigation strategy is implemented and maintained: Server application hardening
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Harden operating systems based on vendor guidance and ASD guidance. Remove unneeded software, services and ports.
- Evidence the mitigation strategy is implemented and maintained: Operating system hardening
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Antivirus software using heuristics and reputation ratings to check a file's prevalence and digital signature prior to execution.
- Evidence the mitigation strategy is implemented and maintained: Antivirus software with heuristics
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Control removable storage media and connected devices. Block USB storage devices. Disable AutoRun/AutoPlay.
- Evidence the mitigation strategy is implemented and maintained: Control removable storage media
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Block spoofed emails. Use Sender Policy Framework (SPF) or Sender ID to check incoming emails. Use DKIM and DMARC for outgoing emails.
- Evidence the mitigation strategy is implemented and maintained: Block spoofed emails
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
User education regarding applicable threats, reporting of suspicious emails, websites and activity, and the consequences of poor security practices.
- Evidence the mitigation strategy is implemented and maintained: User education
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Antivirus software with up-to-date signatures to identify known malware.
- Evidence the mitigation strategy is implemented and maintained: Antivirus software with signatures
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
TLS encryption between email servers to protect the confidentiality of emails in transit between organisations.
- Evidence the mitigation strategy is implemented and maintained: TLS encryption between email servers
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Recovering Data and System Availability
Regular backups of important new/changed data, software and configuration settings, stored disconnected, retained for at least three months. Test restoration initially, annually and when IT infrastructure changes.
- Evidence the mitigation strategy is implemented and maintained: Regular backups
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Business continuity and disaster recovery plans which are tested, including for the scenario of a complete loss of computing capabilities.
- Evidence the mitigation strategy is implemented and maintained: Business continuity and disaster recovery plans
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
System recovery capabilities including standard operating environment images to restore computers to a known good state.
- Evidence the mitigation strategy is implemented and maintained: System recovery capabilities
- Configuration / tooling output demonstrating the strategy
- Coverage across in-scope systems
- Records showing ongoing operation
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASD Strategies to Mitigate Cyber Security Incidents framework page.