Essential Eight
Assess and improve the eight ASD mitigation strategies using a risk-based program aligned to an appropriate target maturity level.
ASD-aligned assessment
Target maturity planning
Technical uplift
Evidence and exceptions
Essential Eight Maturity Requires the Eight Strategies to Work Together
The ASD Essential Eight maturity model supports implementation across eight complementary mitigation strategies. ITFR assesses current implementation and effectiveness, helps select a suitable target and coordinates uplift while documenting approved exceptions and compensating controls.
✓Application control
Reduce unapproved execution through suitable application control policies and management.
✓Patch applications
Identify and remediate application vulnerabilities according to risk and maturity requirements.
✓Microsoft Office macro settings
Restrict macro execution and reduce common malicious-document pathways.
✓User application hardening
Harden browsers, productivity applications and supported user-facing software.
✓Restrict administrative privileges
Limit, separate and review privileged access and administrative activity.
✓Patch operating systems, MFA and backups
Coordinate remaining core strategies across systems, identities and recovery.
The result: a clearer Essential Eight maturity position, prioritised uplift work and evidence that explains implemented controls, gaps and approved exceptions.
Benefits at a glance
Clear Maturity Baseline
Risk-Based Target
Coordinated Uplift
Better Evidence
GOVERN IT · ESSENTIAL EIGHT
Choose the Right Essential Eight Engagement
Choose an assessment for an evidence-led maturity baseline or an uplift program to implement and validate priority improvements.
Essential Eight Assessment
Evidence-Led Reviewagainst the selected target maturity
Establish current maturity and priority gaps
For organisations that need a defensible view of how the eight mitigation strategies are implemented and operating.
- Included: Scope & Target ConfirmationConfirm systems, users, services and the maturity level being assessed.
- Included: Implementation ReviewReview design and coverage across all eight mitigation strategies.
- Included: Effectiveness TestingSample settings, records, devices and processes to test control operation.
- Included: Exception ReviewIdentify exclusions, approvals, compensating controls and residual risk.
- Included: Maturity FindingsRecord satisfied, partial and unmet requirements against the agreed model.
- Included: Prioritised Uplift RoadmapDefine actions, dependencies, owners and recommended sequencing.
BEST FOR
Businesses that need a current Essential Eight maturity baseline and clear improvement priorities.
Essential Eight Uplift Program
Guided Implementationagainst the selected target maturity
Assessment, remediation and validation
For organisations that want help closing priority gaps and moving toward an agreed target maturity level.
- Included: Everything in the Essential Eight AssessmentScope, implementation review, testing, exceptions, findings and roadmap.
- Included: Control Design & RemediationDevelop practical settings, processes and technical improvements.
- Included: Patching & Vulnerability UpliftImprove application and operating system patch coverage and timing.
- Included: Identity & Privilege UpliftStrengthen MFA, administrative privileges and account controls.
- Included: Application & User HardeningImplement application control, macro restrictions and user application hardening.
- Included: Backup & Recovery ImprovementImprove backup protection, access and recovery validation.
- Included: Retesting & Evidence UpdateValidate agreed improvements and update findings, exceptions and evidence.
BEST FOR
Businesses that need coordinated technical uplift and validation rather than an assessment report alone.
Use the arrows or swipe sideways to view every plan.
Target Maturity Should Match Risk and Environment
The model defines Maturity Level Zero through Maturity Level Three, with Levels One to Three addressing increasing tradecraft.
ITFR can help select a suitable target and progressively improve all eight strategies while keeping exceptions narrow, approved and reviewed.
You pursue a justified target rather than choosing a maturity level only because it sounds higher.
COMMON QUESTIONS
Your Essential Eight questions, answered
Can we start by assessing our current maturity?
Yes. An assessment can review the agreed systems and controls, identify gaps and establish evidence for a practical improvement plan. Scope and assessment expectations are confirmed first.
Does every organisation need the same target maturity?
The target should reflect business risk and any confirmed customer, contractual or assurance requirements. ITFR can help plan the technical work around the agreed target and environment.
Can you implement improvements after the assessment?
ITFR can scope uplift across relevant identity, patching, hardening, application and backup controls, with responsibilities and priorities agreed with your team.
What happens when a control cannot be implemented immediately?
Document the constraint, business owner, risk, agreed treatment and any compensating measures. Exceptions should be reviewed rather than treated as permanent without oversight.
Is Essential Eight the same as ISO 27001?
No. Essential Eight focuses on a set of cyber mitigation strategies. ISO 27001 addresses an information security management system. They can support different parts of a broader security program.
READY TO GET STARTED?
Turn Essential Eight gaps into practical improvements
Talk to us about your environment, current controls and the maturity you need to work towards.






