North Ark
← All resources

LM-08 · Secure · Interactive

Essential Eight Self-Score

Rate each ACSC strategy from not implemented through ML3. Use this before customer security questionnaires — then validate with a proper assessment.

Self-assessment only — not an audit. For customer-ready attestation, see FC-03 E8 QuickScan.

Application control

Prevent execution of unapproved programs

Patch applications

Patch within 48 hours for extreme risk

Patch operating systems

OS patches applied on SLA by risk

Restrict admin privileges

Just-in-time admin; separate accounts

Application hardening

Disable macros, harden browsers

Multi-factor authentication

MFA for all users to internet services

Daily backups

Tested backups; offline or immutable copy

User application hardening

Block risky features in user apps