Checklist
Essential Eight self-assessment checklist
Use this to get a first view of where you stand against each of the eight strategies. It is a starting point for a conversation with your team, and it doesn't replace an assessment that tests controls against evidence.
How to use it
Answer yes only if you could show evidence today: a configuration, a report or a test result. If the answer is "we think so", mark it as a gap. Work through it with the people who run each area, and note which systems are the exceptions.
Application control
- Is application control enforced on workstations, not only in audit mode?
- Are executables, scripts and installers blocked from running in user profile and temporary folders?
- Are the rules based on publishers or hashes, rather than broad folder paths?
- Is there a process for approving new applications, and is it used?
- Are blocked execution events logged and reviewed?
Read the rest of this checklist
Enter your work details to unlock this and every other guide on the site. We'll also send you a note in case you want to talk it through with an engineer.
Patch applications
- Do you have an up-to-date inventory of the applications installed across the estate?
- Are internet-facing services, browsers, Office, PDF readers and email clients patched within timeframes you could show?
- Is vulnerability scanning run regularly across workstations and servers?
- Are applications that are no longer supported by their vendor removed?
Configure Microsoft Office macro settings
- Are macros blocked for users who don't have a business need for them?
- Are macros in files from the internet blocked?
- Is macro antivirus scanning enabled?
- Can users change these settings themselves?
User application hardening
- Do browsers block Java and web advertisements from the internet?
- Is Internet Explorer 11 disabled or removed?
- Can users change browser security settings?
- Is PowerShell constrained for users who don't need it?
Restrict administrative privileges
- Are privileged accounts separate from the accounts people use for email and browsing?
- Is privileged access reviewed and removed when it is no longer needed?
- Are privileged accounts prevented from accessing the internet and email?
- Is just-in-time elevation used for administrative roles in Entra ID?
- Are break-glass accounts documented, protected and tested?
Patch operating systems
- Are workstation and server operating systems patched within timeframes you could show?
- Are network devices and other internet-facing systems included?
- Are operating systems that are no longer supported replaced or isolated?
- Can you produce a patch compliance report for every system group?
Multi-factor authentication
- Is MFA required for every user of online services, including Microsoft 365?
- Is MFA required for remote access and for every privileged account?
- Is legacy authentication blocked?
- Are phishing-resistant methods, such as FIDO2 keys, passkeys or Windows Hello for Business, used for administrators?
Regular backups
- Are important data, software and configuration backed up on a schedule that matches business needs?
- Have restores been tested, and can you show the results?
- Are backups protected from modification and deletion, including by administrators' everyday accounts?
- Would backups survive an attacker with domain admin rights?
What your answers mean
Gaps in application control, macro settings and administrative privileges are the most common, and they take the most planning to close because they change how people work. A formal assessment tests each control against the ACSC maturity model, gives a maturity level for each strategy and turns the gaps into a dated uplift plan.
Next step
This guide supports Essential Eight assessment and uplift. Talk to an engineer if you want it worked through for your environment.
Start a conversation
Turn the checklist into evidence.
Talk to an engineer about an Essential Eight assessment.
Talk to an Engineer