Essential Eight

Assess and improve the eight ASD mitigation strategies using a risk-based program aligned to an appropriate target maturity level.

Support

ASD-aligned assessment

Target maturity planning

Technical uplift

Evidence and exceptions

Essential Eight Maturity Requires the Eight Strategies to Work Together

The ASD Essential Eight maturity model supports implementation across eight complementary mitigation strategies. ITFR assesses current implementation and effectiveness, helps select a suitable target and coordinates uplift while documenting approved exceptions and compensating controls.

Application control
Reduce unapproved execution through suitable application control policies and management.

Patch applications
Identify and remediate application vulnerabilities according to risk and maturity requirements.

Microsoft Office macro settings
Restrict macro execution and reduce common malicious-document pathways.

User application hardening
Harden browsers, productivity applications and supported user-facing software.

Restrict administrative privileges
Limit, separate and review privileged access and administrative activity.

Patch operating systems, MFA and backups
Coordinate remaining core strategies across systems, identities and recovery.

The result: a clearer Essential Eight maturity position, prioritised uplift work and evidence that explains implemented controls, gaps and approved exceptions.

Benefits at a glance

Clear Maturity Baseline

Assess implementation and effectiveness against the current agreed maturity model.

Risk-Based Target

Select an appropriate target maturity level for the environment and threat exposure.

Coordinated Uplift

Improve all eight strategies without treating individual controls as unrelated projects.

Better Evidence

Document testing, findings, exceptions, compensating controls and ownership.
GOVERN IT · ESSENTIAL EIGHT

Choose the Right Essential Eight Engagement

Choose an assessment for an evidence-led maturity baseline or an uplift program to implement and validate priority improvements.

Essential Eight Assessment

Evidence-Led Review

against the selected target maturity

Establish current maturity and priority gaps

For organisations that need a defensible view of how the eight mitigation strategies are implemented and operating.

Scope & Target Confirmation
Confirm systems, users, services and the maturity level being assessed.

Implementation Review
Review design and coverage across all eight mitigation strategies.

Effectiveness Testing
Sample settings, records, devices and processes to test control operation.

Exception Review
Identify exclusions, approvals, compensating controls and residual risk.

Maturity Findings
Record satisfied, partial and unmet requirements against the agreed model.

Prioritised Uplift Roadmap
Define actions, dependencies, owners and recommended sequencing.

 

BEST FOR

Businesses that need a current Essential Eight maturity baseline and clear improvement priorities.

Essential Eight Uplift Program

Guided Implementation

against the selected target maturity

Assessment, remediation and validation

For organisations that want help closing priority gaps and moving toward an agreed target maturity level.

Everything in the Essential Eight Assessment
Scope, implementation review, testing, exceptions, findings and roadmap.

Control Design & Remediation
Develop practical settings, processes and technical improvements.

Patching & Vulnerability Uplift
Improve application and operating system patch coverage and timing.

Identity & Privilege Uplift
Strengthen MFA, administrative privileges and account controls.

Application & User Hardening
Implement application control, macro restrictions and user application hardening.

Backup & Recovery Improvement
Improve backup protection, access and recovery validation.

Retesting & Evidence Update
Validate agreed improvements and update findings, exceptions and evidence.

BEST FOR

Businesses that need coordinated technical uplift and validation rather than an assessment report alone.

Target Maturity Should Match Risk and Environment

The model defines Maturity Level Zero through Maturity Level Three, with Levels One to Three addressing increasing tradecraft.

ITFR can help select a suitable target and progressively improve all eight strategies while keeping exceptions narrow, approved and reviewed.

You pursue a justified target rather than choosing a maturity level only because it sounds higher.

ESSENTIAL EIGHT EXPERTISE

Need Help Establishing Your Current Maturity?

ITFR can assess implementation and effectiveness, identify practical gaps and define a staged uplift program.

1

Maturity Assessment

Review all eight strategies against the agreed current ASD model.

2

Technical Uplift

Implement practical identity, patching, hardening, application and backup controls.

3

Exception Management

Document exclusions, approvals, compensating controls and residual risk.

4

Evidence & Retesting

Test operation and maintain evidence as controls and requirements change.

$

Match Essential Eight work to target maturity, scope and current capability.

Choose assessment or uplift according to assurance needs, technical gaps, internal capacity and business risk.