A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.
53 terms and 32 ASD source documents · all sourced to cyber.gov.au · last checked 26 August 2026 · Essential Eight Maturity Model (November 2023)
Several distinctions directly change an assessment's scope. An online service may sit behind a perimeter firewall, a privileged user account may belong to a person or a service, and a compensating control is not the same as an exception.
The eight mitigation strategies each have their own page, and the definitions here link through to them. For the framework itself, start with the Essential Eight guide; for what each strategy requires at each level, the requirements matrix has every row. To see where your own organisation sits, the self-assessment scores the same requirements against your answers.
No terms match “”.
The eight strategies
The mitigation strategies themselves. Each one has its own page setting out what it requires at every maturity level.
Application control
Application control is a security control that permits only an organisation-approved set of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to execute. Under the Essential Eight Maturity Model it is one of eight baseline mitigation strategies, mapped to ISM control ISM-1657.
Multi-factor authentication is authentication using two or more different authentication factors: something the claimant knows, something they have, or something they are. Under the Essential Eight it must use something users have plus something they know, or something they have unlocked by something they know or are — and must be phishing-resistant from Maturity Level Two.
Patch applications is the Essential Eight mitigation strategy requiring organisations to find and remediate vulnerabilities in application software within defined timeframes, and to remove applications no longer supported by their vendor. Online services carry the shortest timeframe: 48 hours where a vulnerability is critical or a working exploit exists.
Patch operating systems is the Essential Eight mitigation strategy requiring vulnerabilities in operating systems on workstations, servers and network devices to be remediated within defined timeframes, and unsupported operating systems to be replaced. Internet-facing systems carry a 48-hour clock for critical or actively exploited vulnerabilities.
Regular backups is the Essential Eight mitigation strategy requiring backups of data, applications and settings to be performed and retained according to business criticality and continuity requirements, synchronised to a common restoration point, tested in disaster recovery exercises, and protected from accounts that could delete them.
Restrict administrative privileges is the Essential Eight mitigation strategy limiting privileged access to what users need, separating privileged from unprivileged environments, and preventing privileged accounts from reaching the internet, email and web services — with the explicit exception of accounts authorised to administer online services.
Restrict Microsoft Office macros is the Essential Eight mitigation strategy governing embedded Visual Basic for Applications code in Office files. It requires macros to be disabled for users without a demonstrated business requirement, blocked in files originating from the internet, scanned by antivirus, and locked against user modification of the settings.
User application hardening is the Essential Eight mitigation strategy that disables or restricts risky features in the software users run every day: web browsers, Office productivity suites, PDF software and PowerShell. It shrinks the attack surface those applications expose, rather than protecting applications an organisation develops.
What the Essential Eight is, the document that defines it, and the longer list of 37 strategies it was drawn from.
E8MM
Essential Eight Maturity Model
The publication that defines what each mitigation strategy requires at each maturity level. ASD's current published release is dated November 2023, and its publication page was last updated on 27 November 2023.
ASD's baseline set of eight mitigation strategies for internet-connected information technology networks. They are the strategies rated "essential" in the broader Strategies to Mitigate Cyber Security Incidents publication. Essential 8 and E8 are common abbreviations for the same framework.
ASD's proposed evolution of the Essential Eight, announced on 15 June 2026. The broader series will be grounded in the ISM and begin with Essentials for enterprise IT. Consultation ran until 12 July 2026. The announcement does not set a publication or Essential Eight retirement date.
A group of related security measures intended to reduce a class of cyber risk. The Essential Eight contains eight such strategies; ASD's broader 2017 publication contains 37. A strategy meets a maturity level only when every requirement at that level is assessed as effective or alternate control.
ASD's February 2017 publication of 37 mitigation strategies, from which the eight rated "essential" are drawn. It remains published separately from the maturity model. Its backup guidance includes retention for at least three months; the current maturity model instead ties retention to business criticality and continuity requirements.
The four-point scale and what it measures. Requirements are cumulative within a strategy, and an organisation's overall level is its weakest strategy rather than its average.
Maturity Level One
Addresses adversaries using widely available commodity tradecraft, such as public exploits against unpatched online services or stolen, reused, brute-forced or guessed credentials. These adversaries seek opportunistic targets. ASD says this level may suit small to medium enterprises.
Addresses more adaptive adversaries who rely less on public tools and techniques. They may rapidly use new exploits, socially engineer users to help bypass controls and steal authentication tokens to defeat stronger MFA. ASD says this level may suit critical infrastructure and high-threat environments, but warns that it cannot stop every sufficiently resourced adversary.
Addresses adversaries with a modest increase in capability who invest more time in a target and their tools. Their methods include credential phishing and attempts to circumvent weaker MFA. ASD says this level may suit large enterprises. Separate PSPF and Defence requirements mandate it for non-corporate Commonwealth entities and DISP members respectively.
The result recorded when an implementation does not meet Maturity Level One. It signifies weaknesses that could enable compromise of the confidentiality of data or the integrity or availability of systems and data. It is not a target maturity level.
The maturity level an organisation plans to reach based on its attractiveness to adversaries and the consequences of compromise. ASD advises organisations to progress one level at a time and reach the same level across all eight strategies before moving higher. Stronger measures may be implemented early without penalty.
How an assessor records a result, and what ASD accepts as proof that a control is in place. A policy stating intent sits at the bottom of that hierarchy.
Assessment outcomes
The Essential Eight Assessment Process Guide defines seven results for a control. They are not assessed, effective, alternate control, ineffective, no visibility, not implemented and not applicable. To claim a maturity level for a strategy, every control must be assessed as effective or alternate control.
An alternative measure used when a specific Essential Eight requirement cannot be met. The system owner must show that it provides equivalent protection to the original requirement. If the assessor finds it suitable and effective, the assessment outcome is "alternate control".
ASD ranks assessment evidence in four tiers. Excellent evidence tests a control with a simulated activity. Good evidence reviews live configuration through the system interface. Fair evidence reviews a copy, such as a report or screenshot. A policy or verbal statement is poor evidence.
A documented and approved departure from a requirement. ASD says exceptions should be minimised in number and scope, reviewed regularly and not approved beyond one year. An exception supported by suitable compensating controls may still allow the target level to be met; risk acceptance alone does not.
The systems and data to which each requirement applies. "Online service" and "internet-facing server" have distinct meanings, and those meanings determine which patching requirements apply.
Customer
ASD defines a customer as a person with whom an organisation has dealings, usually through the consumption of goods or services. A purchase is not required. The maturity model includes MFA requirements for customer access to online customer services that handle sensitive customer data.
ASD defines a data repository as a location where data is stored, managed and made available to users. At Maturity Level Three, its users must authenticate with phishing-resistant MFA.
ASD defines a high-value server as one that provides important network services or contains data repositories. Examples include Domain Name System, database, email, file and web servers. A critical server is a separate category that provides critical network or security services, such as a domain controller.
A subset of online services designed specifically for interaction between an organisation and its customers; myGov is ASD's example. From Maturity Level One, customers must use MFA to access these services when they process, store or communicate sensitive customer data.
Any service directly accessible over the internet, including one behind a perimeter firewall. Examples include a web portal, cloud service, firewall or VPN concentrator. The term scopes application-patching requirements. It is distinct from "internet-facing server", which the maturity model uses for operating-system patching.
ASD defines sensitive data as data that would cause damage to an organisation or individual if compromised. For sensitive customer data, the Essential Eight FAQ directs organisations to the Office of the Australian Information Commissioner. Its guidance applies the Privacy Act 1988.
Any device that uses a desktop operating system, such as Microsoft Windows or a Linux distribution. ASD includes desktop PCs, laptops and some tablets. The distinction between workstations and servers affects the scope of application-control and patching requirements.
Accounts, their privileges and the authentication that protects them. A service account may be privileged or unprivileged, while specific Essential Eight credential requirements apply to service accounts at Maturity Level Two.
Break glass account
An emergency account used when normal privileged access is unavailable. From Maturity Level Two, credentials for break glass accounts, local administrator accounts and service accounts must be long, unique, unpredictable and managed. Separate ISM guidance specifies a minimum of 30 characters.
ASD defines a jump server as a computer used to manage important or critical resources in a separate security domain. It is also called a jump host or jump box. From Maturity Level Two, administrative activities must be performed through jump servers.
Authentication performed in stages instead of requiring two or more factors for the same authentication event. ASD says it is not a suitable substitute for MFA because an adversary may compromise each stage separately without overcoming a multi-factor check.
MFA that is less susceptible to brute-force and machine-in-the-middle attacks than passwords or weaker methods such as SMS, email and voice calls. ASD names smart cards, security keys, Windows Hello for Business and passkeys, and prefers FIDO2 Level 2 certification over Level 1. From Maturity Level Two, specified MFA for online services and systems must be phishing-resistant. Maturity Level Three extends the requirement to data repositories and all relevant customer authentication.
An account that can modify system configurations, account privileges, event logs or security settings. It also includes an account with limited privileges that can bypass system controls. A privileged user account may belong to a person or a service.
A hardened workstation or virtualised privileged operating environment used specifically for administrative activities. ASD treats Secure Admin Workstation (SAW) and Privileged Access Workstation (PAW) as names for the same concept, and does not strictly require dedicated physical hardware. The Essential Eight requires SAWs at Maturity Level Three.
An account used to perform automated tasks without manual intervention and typically configured to prevent interactive login. A service account may be privileged or unprivileged. Regardless, the Maturity Level Two credential requirement expressly covers service accounts.
What ASD means by a vulnerability, how vendor criticality differs from evidence of a working exploit, and when the 48-hour patching timeframe applies.
Critical vulnerability
ASD uses the vendor's criticality assessment rather than defining a separate rating. Examples include vulnerabilities that enable an authentication bypass with privileged access or remote code execution without user interaction. If a vendor provides no rating, ASD suggests considering the vulnerability type and its CVSS score. CISA's Known Exploited Vulnerabilities Catalog can instead help establish whether exploitation is occurring.
ASD defines a vulnerability as a weakness in a system's security requirements, design, implementation or operation. It can be triggered accidentally or exploited intentionally, resulting in a violation of the system's security policy.
ASD separates a cyber security event from a cyber security incident, and the logging requirements are written in those terms.
Cyber security event
ASD defines a cyber security event as "an occurrence of a system, service or network state indicating a possible breach of security policy, failure of safeguards or a previously unknown situation that may be relevant to security". An event is not necessarily an incident.
ASD defines a cyber security incident as an unwanted or unexpected event, or series of events, that has compromised business operations or has a significant probability of doing so. From Maturity Level Two, incidents must be reported promptly to the CISO or a delegate and to ASD. The incident response plan must also be enacted.
The specific settings, tools and file formats the requirements name. Where a requirement names something exactly, it is defined here.
Constrained Language Mode
A PowerShell execution mode that restricts language features and access to APIs, libraries and classes that can be abused. The Essential Eight requires it at Maturity Level Three under user application hardening.
Essential Eight Maturity Verification Tool, Application Control Verification Tool
The Essential Eight Maturity Verification Tool and Application Control Verification Tool are available through ASD's Partner Portal. They support technical testing of an implementation. ASD ranks direct testing and live configuration review above copied reports, screenshots, policies or verbal statements.
Machine-readable Essential Eight baselines expressed in Open Security Controls Assessment Language (OSCAL). ASD provides them through the ISM so governance, reporting and compliance tools can ingest and track implementation data.
A folder from which Microsoft Office macros can run without prompting. ASD discourages trusted documents but accepts securely implemented trusted locations. At Maturity Level Three, only privileged users responsible for validating macros may write to these locations, and macros must first be checked for malicious code.
A newer digital-signature format for Microsoft Office macros. At Maturity Level Three, macros signed with formats other than V3 cannot be enabled through the Message Bar or Backstage View. ASD introduced the control because older digitally signed macros could be altered without invalidating the file's signature.
The organisations that publish the framework and the separate policies, contracts and laws that make particular maturity levels mandatory for some organisations.
ACSC
Australian Cyber Security Centre
The Australian Cyber Security Centre is the Australian Government's technical authority on cyber security and sits within the Australian Signals Directorate. Current publications use the name "ASD's ACSC". The ACSC is part of ASD, not an interchangeable name for the whole agency.
The Australian Government agency that contains the ACSC and publishes the Essential Eight, the Information Security Manual and the Strategies to Mitigate Cyber Security Incidents. The maturity model does not require independent certification, although a policy, regulator or contract may require an independent assessment.
The Department of Defence program whose membership is required for some Defence work. All DISP members must achieve and maintain the full Essential Eight at Maturity Level Two. Assessments against the former "top four" ended on 15 November 2025. The DISP Cyber Security Questionnaire covers 107 Essential Eight controls.
An ASD program that endorses qualified professionals to conduct independent security assessments. IRAP assessors use the Information Security Manual, but they do not accredit, certify, endorse or register systems on ASD's behalf. An IRAP assessment is not an Essential Eight certification.
ASD's cyber security framework and catalogue of individual controls, published quarterly. The current release is June 2026. ISM control applicability is based on the classification of data a system handles, while the Essential Eight prioritises controls by adversary tradecraft and targeting. Each ISM control shows its Essential Eight mapping, or N/A.
The Australian Government protective security framework administered by Home Affairs. Policy 10 requires non-corporate Commonwealth entities to implement the Essential Eight at Maturity Level Two; that requirement took effect on 1 July 2022. The PSPF represents better practice, rather than a mandate, for corporate Commonwealth entities and wholly owned Commonwealth companies.
A software-development principle under which security is designed into every stage of a product or service. Secure by Default concerns secure initial configuration, while Secure by Demand concerns customers seeking evidence of a supplier's security commitments. These are separate ASD product-security principles, not Essential Eight maturity requirements.
The Security of Critical Infrastructure Act 2018 supports risk-management program rules for covered critical infrastructure assets. Those rules offer five cyber security framework options, including the Essential Eight, rather than requiring that framework exclusively. Since 9 June 2026, specified assets in nine higher-risk classes that choose the Essential Eight must meet Maturity Level Two; other framework options have their own stated thresholds.
Everything here is built from these. Go to them rather than to us — and note the
split: ASD recommends the Essential Eight, while the instruments under
“What actually mandates it” are the ones that require it.
The Essential Eight
ASD's own publications. Start with the maturity model — it is what assessments are conducted against.
The full 37 strategies the eight are drawn from. Still live, but a different document — the source of the "three months" backup figure that is not in the maturity model.
The 2026 enhanced rules retain five framework options and set Maturity Level Two for specified assets in nine higher-risk classes that choose the Essential Eight.
Of ten WA entities audited, seven overstated their self-assessed maturity and five had not reached Level One in any control.
32 documents. ASD restructured cyber.gov.au in 2025, so some older paths now
404 — these are the paths that resolved when this page was last checked.
Spotted one that has moved?
Tell us.
Common questions
Why does the definition of "online service" matter so much?
ASD defines an online service as any service directly accessible over the internet, including one behind a perimeter firewall. For these services, critical vulnerabilities and vulnerabilities with working exploits enter the 48-hour application-patching tier. Do not substitute "internet-facing server": the maturity model uses that separate term for operating-system patching.
What is the difference between a compensating control and an exception?
A compensating control is an alternative measure that provides equivalent protection to a specific requirement. An assessor can record a suitable measure as an "alternate control". An exception is a documented and approved departure from a requirement; ASD says it should not be approved beyond one year. Risk acceptance without suitable compensating controls cannot justify omitting an entire strategy: ASD assesses that strategy, and the overall implementation, at Maturity Level Zero.
Is "Essential 8" the same as "Essential Eight"?
Yes — ASD writes it as "Essential Eight" in its own publications, but "Essential 8" and "E8" are common in industry and search. There is no difference in meaning. Similarly, "E8MM" is the Essential Eight Maturity Model.
The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.
Essential Eight
Need this assessed rather than defined?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.