Skip to content

Essential Eight

What is Essential Eight?

Eight mitigation strategies recommended by the Australian Signals Directorate to protect organisations against cyber threats. The Essential Eight covers application control, patching, macro settings, user application hardening, admin privileges, MFA, backups, and patching operating systems.

Compliance

Each of these is named in at least one of the same controls as essential eight. The number is how many controls name both.

What the standards actually require on essential eight

Requirements naming essential eight across 6 standards, quoted from the control text.

Per PSPF Information Security: protect official information. Requirements include (a) implement Essential Eight Maturity Model aligned to data sensitivity + (b) implement Information Security Manual (ISM) controls + (c) protect classified information per Austr...

PSPF24-2 · Information Security, Cybersecurity Maturity, Essential Eight

Implement the Australian Signals Directorate's Essential Eight strategies to mitigate targeted cyber incidents, and self-assess maturity using the Essential Eight Maturity Model.

ASIC-CR-PR-1 · Implement the ASD Essential Eight

The entity must demonstrate that it meets or exceeds the ACSC Essential Eight mitigation strategies at Maturity Level 2 across the corporate ICT systems used to correspond with Defence.

DISP-ICT-E8 · Essential Eight Maturity Level 2 on corporate ICT

Within the period specified by the Rules, the responsible entity must adopt and maintain compliance with one of the recognised cyber security frameworks for the cyber and information security hazard, such as the ACSC Essential Eight (Maturity Level One), ISO/I...

CIRMP-s8-FW · Adoption of a recognised cyber security framework

Per APPs 10-11: quality + security. Requirements include (a) implement APP 10 - Quality of Personal Information - take reasonable steps to ensure personal information is accurate + up-to-date + complete + relevant + (b) implement APP 11 - Security of Personal...

AUPRV-4 · APP 10-11 Quality, Security of Personal Information

Per AUPA 2024 enhancing APP 11: technical and organisational measures. Requirements include (a) implement enhanced Technical and Organisational Security Measures clarifying reasonable steps + (b) implement encryption + access control + activity logging + (c) c...

AUPA24-G · Technical and Organisational Security Measures (APP 11 Enhanced)

Questions people ask about essential eight

What is Essential Eight?
Eight mitigation strategies recommended by the Australian Signals Directorate to protect organisations against cyber threats. The Essential Eight covers application control, patching, macro settings, user application hardening, admin privileges, MFA, backups, and patching operating systems.
Why is Essential Eight important for compliance?
Essential Eight is a key concept in Compliance. Understanding essential eight helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Essential Eight?
Essential Eight appears in the requirement text of Protective Security Policy Framework (PSPF) Release 2024, ASIC Cyber Resilience Good Practices, Defence Industry Security Program (DISP), Critical Infrastructure Risk Management Program (CIRMP) Rules 2023, Privacy Act 1988 (Australia). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Essential Eight?
Explore our compliance framework pages to see how essential eight applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Essential Eight applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.