The Essential Eight is the Australian Cyber Security Centre's baseline set of mitigation strategies. It is short, specific and widely referenced in contracts, insurance questionnaires and board reports, which is why so many IT leaders are now asked the same question: what maturity level are we at?
The eight strategies
The eight are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. Together they aim to stop malware running, limit the damage of an incident and make recovery possible.
What the maturity levels mean
The ACSC's Essential Eight Maturity Model defines levels zero to three. Each level is built around the kind of adversary it is designed to resist, rather than around how much effort has been spent.
Maturity Level One targets opportunistic attackers using commodity tools and widely available exploits. Level Two targets attackers who invest more time, use more capable tools and are more selective about their targets. Level Three targets adaptive attackers who are less reliant on public tools and are prepared to work around weak controls.
Maturity Level Zero means the requirements of Level One are not fully met for that strategy. It is common for an organisation to sit at zero for one or two strategies, often application control or macro settings, while being at one or two for the rest.
Levels are per strategy
Maturity is assessed for each strategy separately. An organisation might be at Level Two for MFA, Level One for patching and Level Zero for application control. The ACSC advises reaching the same target level across all eight before moving any of them higher, because an attacker will use the weakest one.
The model is also revised from time to time. Requirements such as patch timeframes and the type of MFA expected at each level have changed in past updates, so check which version your contract or auditor refers to.
Choosing a target
Level One is the sensible first target for most organisations, and it is the level some regulatory frameworks reference. Level Two is where organisations holding sensitive data, supplying government or operating critical infrastructure usually aim. Level Three is demanding, and is normally reserved for organisations that expect to be targeted by capable adversaries.
Pick the target from your obligations and your threat model, then plan the uplift strategy by strategy. The expensive mistake is committing to a level in a contract before anyone has measured where you are today.
Need to reach and prove an Essential Eight level? Essential Eight, done for you
All resources
