Nano Solutions

Reference

Essential Eight glossary

A sourced guide to terms used in ASD's Essential Eight publications and in the separate instruments that make the framework mandatory for some organisations.

53 terms and 32 ASD source documents · all sourced to cyber.gov.au · last checked 26 August 2026 · Essential Eight Maturity Model (November 2023)

Definitions use ASD's wording where precision matters and otherwise explain it in plain language. Primary sources include the ISM cyber security terminology chapter, the Essential Eight Maturity Model, its FAQ and the separate instruments linked with relevant entries.

Several distinctions directly change an assessment's scope. An online service may sit behind a perimeter firewall, a privileged user account may belong to a person or a service, and a compensating control is not the same as an exception.

The eight mitigation strategies each have their own page, and the definitions here link through to them. For the framework itself, start with the Essential Eight guide; for what each strategy requires at each level, the requirements matrix has every row. To see where your own organisation sits, the self-assessment scores the same requirements against your answers.

No terms match “”.

The eight strategies

The mitigation strategies themselves. Each one has its own page setting out what it requires at every maturity level.

Application control

Application control is a security control that permits only an organisation-approved set of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to execute. Under the Essential Eight Maturity Model it is one of eight baseline mitigation strategies, mapped to ISM control ISM-1657.

ISM control ISM-1657 Full requirements →

Multi-factor authentication

Multi-factor authentication is authentication using two or more different authentication factors: something the claimant knows, something they have, or something they are. Under the Essential Eight it must use something users have plus something they know, or something they have unlocked by something they know or are — and must be phishing-resistant from Maturity Level Two.

ISM control ISM-1504 Full requirements →

Patch applications

Patch applications is the Essential Eight mitigation strategy requiring organisations to find and remediate vulnerabilities in application software within defined timeframes, and to remove applications no longer supported by their vendor. Online services carry the shortest timeframe: 48 hours where a vulnerability is critical or a working exploit exists.

ISM control ISM-1690 Full requirements →

Patch operating systems

Patch operating systems is the Essential Eight mitigation strategy requiring vulnerabilities in operating systems on workstations, servers and network devices to be remediated within defined timeframes, and unsupported operating systems to be replaced. Internet-facing systems carry a 48-hour clock for critical or actively exploited vulnerabilities.

ISM control ISM-1701 Full requirements →

Regular backups

Regular backups is the Essential Eight mitigation strategy requiring backups of data, applications and settings to be performed and retained according to business criticality and continuity requirements, synchronised to a common restoration point, tested in disaster recovery exercises, and protected from accounts that could delete them.

ISM control ISM-1511 Full requirements →

Restrict administrative privileges

Restrict administrative privileges is the Essential Eight mitigation strategy limiting privileged access to what users need, separating privileged from unprivileged environments, and preventing privileged accounts from reaching the internet, email and web services — with the explicit exception of accounts authorised to administer online services.

ISM control ISM-1507 Full requirements →

Restrict Microsoft Office macros

Restrict Microsoft Office macros is the Essential Eight mitigation strategy governing embedded Visual Basic for Applications code in Office files. It requires macros to be disabled for users without a demonstrated business requirement, blocked in files originating from the internet, scanned by antivirus, and locked against user modification of the settings.

ISM control ISM-1671 Full requirements →

User application hardening

User application hardening is the Essential Eight mitigation strategy that disables or restricts risky features in the software users run every day: web browsers, Office productivity suites, PDF software and PowerShell. It shrinks the attack surface those applications expose, rather than protecting applications an organisation develops.

Full requirements →

The framework

What the Essential Eight is, the document that defines it, and the longer list of 37 strategies it was drawn from.

Essential Eight

ASD's baseline set of eight mitigation strategies for internet-connected information technology networks. They are the strategies rated "essential" in the broader Strategies to Mitigate Cyber Security Incidents publication. Essential 8 and E8 are common abbreviations for the same framework.

Read more → See also: E8MM, Strategies to Mitigate Cyber Security Incidents, Essentials series

Essentials series

ASD's proposed evolution of the Essential Eight, announced on 15 June 2026. The broader series will be grounded in the ISM and begin with Essentials for enterprise IT. Consultation ran until 12 July 2026. The announcement does not set a publication or Essential Eight retirement date.

Read more → Source ↗ See also: Essential Eight, ISM

Mitigation strategy

A group of related security measures intended to reduce a class of cyber risk. The Essential Eight contains eight such strategies; ASD's broader 2017 publication contains 37. A strategy meets a maturity level only when every requirement at that level is assessed as effective or alternate control.

See also: Maturity Level Zero, Essential Eight

Strategies to Mitigate Cyber Security Incidents

ASD's February 2017 publication of 37 mitigation strategies, from which the eight rated "essential" are drawn. It remains published separately from the maturity model. Its backup guidance includes retention for at least three months; the current maturity model instead ties retention to business criticality and continuity requirements.

Source ↗ See also: Essential Eight, Regular backups

Maturity levels

The four-point scale and what it measures. Requirements are cumulative within a strategy, and an organisation's overall level is its weakest strategy rather than its average.

Maturity Level One

Addresses adversaries using widely available commodity tradecraft, such as public exploits against unpatched online services or stolen, reused, brute-forced or guessed credentials. These adversaries seek opportunistic targets. ASD says this level may suit small to medium enterprises.

See also: Maturity Level Two, Target maturity level

Maturity Level Three

Addresses more adaptive adversaries who rely less on public tools and techniques. They may rapidly use new exploits, socially engineer users to help bypass controls and steal authentication tokens to defeat stronger MFA. ASD says this level may suit critical infrastructure and high-threat environments, but warns that it cannot stop every sufficiently resourced adversary.

See also: Maturity Level Two, Target maturity level

Maturity Level Two

Addresses adversaries with a modest increase in capability who invest more time in a target and their tools. Their methods include credential phishing and attempts to circumvent weaker MFA. ASD says this level may suit large enterprises. Separate PSPF and Defence requirements mandate it for non-corporate Commonwealth entities and DISP members respectively.

See also: Maturity Level One, Maturity Level Three, PSPF, DISP

Maturity Level Zero

The result recorded when an implementation does not meet Maturity Level One. It signifies weaknesses that could enable compromise of the confidentiality of data or the integrity or availability of systems and data. It is not a target maturity level.

See also: Maturity Level One, Mitigation strategy

Target maturity level

The maturity level an organisation plans to reach based on its attractiveness to adversaries and the consequences of compromise. ASD advises organisations to progress one level at a time and reach the same level across all eight strategies before moving higher. Stronger measures may be implemented early without penalty.

See also: Maturity Level One, Maturity Level Two, Maturity Level Three

Assessment and evidence

How an assessor records a result, and what ASD accepts as proof that a control is in place. A policy stating intent sits at the bottom of that hierarchy.

Assessment outcomes

The Essential Eight Assessment Process Guide defines seven results for a control. They are not assessed, effective, alternate control, ineffective, no visibility, not implemented and not applicable. To claim a maturity level for a strategy, every control must be assessed as effective or alternate control.

Source ↗ See also: Evidence quality, Mitigation strategy

Compensating control

An alternative measure used when a specific Essential Eight requirement cannot be met. The system owner must show that it provides equivalent protection to the original requirement. If the assessor finds it suitable and effective, the assessment outcome is "alternate control".

See also: Exception, Assessment outcomes, Maturity Level Zero

Evidence quality

ASD ranks assessment evidence in four tiers. Excellent evidence tests a control with a simulated activity. Good evidence reviews live configuration through the system interface. Fair evidence reviews a copy, such as a report or screenshot. A policy or verbal statement is poor evidence.

See also: Assessment outcomes, Compensating control

Exception

A documented and approved departure from a requirement. ASD says exceptions should be minimised in number and scope, reviewed regularly and not approved beyond one year. An exception supported by suitable compensating controls may still allow the target level to be met; risk acceptance alone does not.

See also: Compensating control, Assessment outcomes

Scope and assets

The systems and data to which each requirement applies. "Online service" and "internet-facing server" have distinct meanings, and those meanings determine which patching requirements apply.

Customer

ASD defines a customer as a person with whom an organisation has dealings, usually through the consumption of goods or services. A purchase is not required. The maturity model includes MFA requirements for customer access to online customer services that handle sensitive customer data.

See also: Online customer service, Sensitive data

Data repository

ASD defines a data repository as a location where data is stored, managed and made available to users. At Maturity Level Three, its users must authenticate with phishing-resistant MFA.

Read more → See also: Multi-factor authentication, Sensitive data

High-value server

ASD defines a high-value server as one that provides important network services or contains data repositories. Examples include Domain Name System, database, email, file and web servers. A critical server is a separate category that provides critical network or security services, such as a domain controller.

See also: Workstation, Online service

Online customer service

A subset of online services designed specifically for interaction between an organisation and its customers; myGov is ASD's example. From Maturity Level One, customers must use MFA to access these services when they process, store or communicate sensitive customer data.

See also: Online service, Multi-factor authentication

Online service

Any service directly accessible over the internet, including one behind a perimeter firewall. Examples include a web portal, cloud service, firewall or VPN concentrator. The term scopes application-patching requirements. It is distinct from "internet-facing server", which the maturity model uses for operating-system patching.

Read more → See also: Online customer service, Patch applications, Workstation

Sensitive data

ASD defines sensitive data as data that would cause damage to an organisation or individual if compromised. For sensitive customer data, the Essential Eight FAQ directs organisations to the Office of the Australian Information Commissioner. Its guidance applies the Privacy Act 1988.

See also: Customer, Online customer service

Workstation

Any device that uses a desktop operating system, such as Microsoft Windows or a Linux distribution. ASD includes desktop PCs, laptops and some tablets. The distinction between workstations and servers affects the scope of application-control and patching requirements.

See also: High-value server, Online service

Identity and access

Accounts, their privileges and the authentication that protects them. A service account may be privileged or unprivileged, while specific Essential Eight credential requirements apply to service accounts at Maturity Level Two.

Break glass account

An emergency account used when normal privileged access is unavailable. From Maturity Level Two, credentials for break glass accounts, local administrator accounts and service accounts must be long, unique, unpredictable and managed. Separate ISM guidance specifies a minimum of 30 characters.

See also: Privileged user account, Service account

Multi-step authentication

Authentication performed in stages instead of requiring two or more factors for the same authentication event. ASD says it is not a suitable substitute for MFA because an adversary may compromise each stage separately without overcoming a multi-factor check.

Read more → See also: Phishing-resistant MFA, Multi-factor authentication

Phishing-resistant MFA

MFA that is less susceptible to brute-force and machine-in-the-middle attacks than passwords or weaker methods such as SMS, email and voice calls. ASD names smart cards, security keys, Windows Hello for Business and passkeys, and prefers FIDO2 Level 2 certification over Level 1. From Maturity Level Two, specified MFA for online services and systems must be phishing-resistant. Maturity Level Three extends the requirement to data repositories and all relevant customer authentication.

Read more → See also: Multi-factor authentication, Multi-step authentication

Secure Admin Workstation

SAW, Privileged Access Workstation, PAW

A hardened workstation or virtualised privileged operating environment used specifically for administrative activities. ASD treats Secure Admin Workstation (SAW) and Privileged Access Workstation (PAW) as names for the same concept, and does not strictly require dedicated physical hardware. The Essential Eight requires SAWs at Maturity Level Three.

Read more → See also: Jump server, Privileged user account

Service account

An account used to perform automated tasks without manual intervention and typically configured to prevent interactive login. A service account may be privileged or unprivileged. Regardless, the Maturity Level Two credential requirement expressly covers service accounts.

See also: Privileged user account, Break glass account

Vulnerabilities and patching

What ASD means by a vulnerability, how vendor criticality differs from evidence of a working exploit, and when the 48-hour patching timeframe applies.

Critical vulnerability

ASD uses the vendor's criticality assessment rather than defining a separate rating. Examples include vulnerabilities that enable an authentication bypass with privileged access or remote code execution without user interaction. If a vendor provides no rating, ASD suggests considering the vulnerability type and its CVSS score. CISA's Known Exploited Vulnerabilities Catalog can instead help establish whether exploitation is occurring.

See also: Vulnerability, Patch applications

Vulnerability

ASD defines a vulnerability as a weakness in a system's security requirements, design, implementation or operation. It can be triggered accidentally or exploited intentionally, resulting in a violation of the system's security policy.

See also: Critical vulnerability, Patch applications

Incidents and logging

ASD separates a cyber security event from a cyber security incident, and the logging requirements are written in those terms.

Cyber security event

ASD defines a cyber security event as "an occurrence of a system, service or network state indicating a possible breach of security policy, failure of safeguards or a previously unknown situation that may be relevant to security". An event is not necessarily an incident.

See also: Cyber security incident

Cyber security incident

ASD defines a cyber security incident as an unwanted or unexpected event, or series of events, that has compromised business operations or has a significant probability of doing so. From Maturity Level Two, incidents must be reported promptly to the CISO or a delegate and to ASD. The incident response plan must also be enacted.

See also: Cyber security event

Settings and tooling

The specific settings, tools and file formats the requirements name. Where a requirement names something exactly, it is defined here.

Constrained Language Mode

A PowerShell execution mode that restricts language features and access to APIs, libraries and classes that can be abused. The Essential Eight requires it at Maturity Level Three under user application hardening.

Read more → See also: User application hardening

E8MVT and ACVT

Essential Eight Maturity Verification Tool, Application Control Verification Tool

The Essential Eight Maturity Verification Tool and Application Control Verification Tool are available through ASD's Partner Portal. They support technical testing of an implementation. ASD ranks direct testing and live configuration review above copied reports, screenshots, policies or verbal statements.

See also: Evidence quality, Application control

OSCAL baselines

Machine-readable Essential Eight baselines expressed in Open Security Controls Assessment Language (OSCAL). ASD provides them through the ISM so governance, reporting and compliance tools can ingest and track implementation data.

See also: ISM, E8MM

Trusted location

A folder from which Microsoft Office macros can run without prompting. ASD discourages trusted documents but accepts securely implemented trusted locations. At Maturity Level Three, only privileged users responsible for validating macros may write to these locations, and macros must first be checked for malicious code.

Read more → See also: V3 signature, Restrict Microsoft Office macros

V3 signature

A newer digital-signature format for Microsoft Office macros. At Maturity Level Three, macros signed with formats other than V3 cannot be enabled through the Message Bar or Backstage View. ASD introduced the control because older digitally signed macros could be altered without invalidating the file's signature.

Read more → See also: Trusted location, Restrict Microsoft Office macros

Bodies and instruments

The organisations that publish the framework and the separate policies, contracts and laws that make particular maturity levels mandatory for some organisations.

ACSC

Australian Cyber Security Centre

The Australian Cyber Security Centre is the Australian Government's technical authority on cyber security and sits within the Australian Signals Directorate. Current publications use the name "ASD's ACSC". The ACSC is part of ASD, not an interchangeable name for the whole agency.

Source ↗ See also: ASD

ASD

Australian Signals Directorate

The Australian Government agency that contains the ACSC and publishes the Essential Eight, the Information Security Manual and the Strategies to Mitigate Cyber Security Incidents. The maturity model does not require independent certification, although a policy, regulator or contract may require an independent assessment.

See also: ACSC, ISM

DISP

Defence Industry Security Program

The Department of Defence program whose membership is required for some Defence work. All DISP members must achieve and maintain the full Essential Eight at Maturity Level Two. Assessments against the former "top four" ended on 15 November 2025. The DISP Cyber Security Questionnaire covers 107 Essential Eight controls.

Source ↗ See also: Maturity Level Two, PSPF

IRAP

Infosec Registered Assessors Program

An ASD program that endorses qualified professionals to conduct independent security assessments. IRAP assessors use the Information Security Manual, but they do not accredit, certify, endorse or register systems on ASD's behalf. An IRAP assessment is not an Essential Eight certification.

Source ↗ See also: ISM

ISM

Information Security Manual

ASD's cyber security framework and catalogue of individual controls, published quarterly. The current release is June 2026. ISM control applicability is based on the classification of data a system handles, while the Essential Eight prioritises controls by adversary tradecraft and targeting. Each ISM control shows its Essential Eight mapping, or N/A.

Source ↗ See also: PSPF, IRAP, OSCAL baselines

PSPF

Protective Security Policy Framework

The Australian Government protective security framework administered by Home Affairs. Policy 10 requires non-corporate Commonwealth entities to implement the Essential Eight at Maturity Level Two; that requirement took effect on 1 July 2022. The PSPF represents better practice, rather than a mandate, for corporate Commonwealth entities and wholly owned Commonwealth companies.

Source ↗ See also: Maturity Level Two, SOCI Act, DISP

Secure by Design

A software-development principle under which security is designed into every stage of a product or service. Secure by Default concerns secure initial configuration, while Secure by Demand concerns customers seeking evidence of a supplier's security commitments. These are separate ASD product-security principles, not Essential Eight maturity requirements.

Read more → See also: ISM

SOCI Act

Security of Critical Infrastructure Act 2018

The Security of Critical Infrastructure Act 2018 supports risk-management program rules for covered critical infrastructure assets. Those rules offer five cyber security framework options, including the Essential Eight, rather than requiring that framework exclusively. Since 9 June 2026, specified assets in nine higher-risk classes that choose the Essential Eight must meet Maturity Level Two; other framework options have their own stated thresholds.

Source ↗ See also: PSPF, Maturity Level One

ASD source documents

Everything here is built from these. Go to them rather than to us — and note the split: ASD recommends the Essential Eight, while the instruments under “What actually mandates it” are the ones that require it.

The Essential Eight

ASD's own publications. Start with the maturity model — it is what assessments are conducted against.

Implementing individual strategies

ASD's detailed guidance for the three strategies it publishes separate implementation papers for.

The Information Security Manual

ASD's quarterly control catalogue. The proposed Essentials series is to be grounded in the ISM.

Secure by Design and architecture

Where ASD addresses organisations that build software, rather than organisations that run a fleet.

Supply chain and cloud

Instruments that mandate it

None of these are ASD documents. ASD recommends the Essential Eight; these are the instruments that require it.

Evidence and audit

Published evidence on implementation and assessment outcomes.

32 documents. ASD restructured cyber.gov.au in 2025, so some older paths now 404 — these are the paths that resolved when this page was last checked. Spotted one that has moved? Tell us.

Common questions

Why does the definition of "online service" matter so much?

ASD defines an online service as any service directly accessible over the internet, including one behind a perimeter firewall. For these services, critical vulnerabilities and vulnerabilities with working exploits enter the 48-hour application-patching tier. Do not substitute "internet-facing server": the maturity model uses that separate term for operating-system patching.

What is the difference between a compensating control and an exception?

A compensating control is an alternative measure that provides equivalent protection to a specific requirement. An assessor can record a suitable measure as an "alternate control". An exception is a documented and approved departure from a requirement; ASD says it should not be approved beyond one year. Risk acceptance without suitable compensating controls cannot justify omitting an entire strategy: ASD assesses that strategy, and the overall implementation, at Maturity Level Zero.

Is "Essential 8" the same as "Essential Eight"?

Yes — ASD writes it as "Essential Eight" in its own publications, but "Essential 8" and "E8" are common in industry and search. There is no difference in meaning. Similarly, "E8MM" is the Essential Eight Maturity Model.

Sources

  • The Essential Eight, explained

    The Essential Eight is ASD's baseline set of eight cyber security mitigation strategies for internet-connected corporate IT. This hub explains what each strategy requires, who must implement it, and what ASD has announced about the proposed Essentials series.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Essential Eight self-assessment

    Twenty-four questions, three per mitigation strategy, one for each maturity level. Scored the way ASD scores: cumulative within a strategy, and capped at your weakest strategy overall.

Essential Eight

Need this assessed rather than defined?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.