What is the Essential Eight?
A plain overview: what the framework is, the eight mitigation strategies, the four maturity levels, and who is expected to meet it.
Start hereApplication control
Application control means only software your organisation has approved is permitted to run. Ever...
Patching applications
Patching applications means keeping the software on your devices current, browsers, office suite...
Restricting Microsoft Office macros
Macros automate tasks inside Office documents, and they are also a well-worn route for deliverin...
User application hardening
Hardening turns off the features attackers abuse but most staff never touch, such as Flash, Java...
Restricting administrative privileges
Administrative accounts can change nearly anything, so this strategy limits who holds them, what...
Multi-factor authentication
MFA demands a second proof of identity beyond a password, so a stolen or guessed password alone ...
Patching operating systems
This strategy keeps the operating systems on workstations, servers and network equipment patched...
Regular backups
This strategy makes sure important data, software and settings are backed up, retained for a sui...
Essential Eight maturity levels explained
Each strategy is rated against four maturity levels, from Level 0 (not aligned) to Level 3 (full...

