RESOURCE · ESSENTIAL EIGHT

Essential Eight Assessment Process

A credible maturity result is based on an agreed boundary, current evidence and technical validation across all eight mitigation strategies.

The ASD Essential Eight Assessment Process Guide provides the authoritative assessment guidance. The overview below explains how its principles apply in practice without replacing the current guidance.

01

Define the Assessment Scope

Agree the system boundary, target maturity, users, devices, applications, services, facilities, service providers and inherited controls. The Essential Eight is assessed as a package, so selectively excluding difficult mitigation strategies does not produce a representative result.

02

Collect Evidence

Collect documentation, configuration data, management-platform reports, identity records, patch and vulnerability data, backup results, logs, interviews and demonstrations. Evidence quality, currency and coverage matter more than volume.

03

Review Each Essential Eight Mitigation Strategy

1. Application control

Review execution controls, rule maintenance, coverage and bypass resistance.

2. Patch applications

Validate application vulnerability identification, patching and treatment of unsupported software.

3. Configure Microsoft Office macro settings

Inspect macro sources, trust controls, user restrictions and monitoring.

4. User application hardening

Review security settings for web browsers, Office, PDF software and other user applications.

5. Restrict administrative privileges

Assess privileged accounts, access paths, administration practices and periodic reviews.

6. Patch operating systems

Validate operating-system vulnerability identification, patch deployment and unsupported platforms.

7. Multi-factor authentication

Assess coverage, factor strength and application to privileged and external access.

8. Regular backups

Review backup coverage, protection, retention, restoration testing and administrative access.

04

Conduct Technical Validation

Assessment should go beyond self-reported answers. The assessor samples systems and accounts, examines configurations and records, observes demonstrations and uses approved testing methods to confirm that controls operate across the boundary.

05

Determine Maturity

Results are compared with the current ASD maturity model. Requirements at higher levels are cumulative, and the outcome must reflect the assessed package rather than an average score across strategies.

06

Identify Gaps

Findings should identify the unmet requirement, affected scope, evidence considered and security consequence. Clear findings distinguish isolated exceptions from systemic control weaknesses.

07

Develop a Remediation Roadmap

Prioritise work according to risk, dependencies and operational feasibility. The roadmap should assign owners, distinguish design from implementation and include the evidence needed to demonstrate completion.

08

Reassess After Uplift

Reassessment validates whether remediation is implemented and effective across the relevant scope. It should test the changed control rather than rely only on a closure statement.

Plan an Essential Eight Assessment

Explore our Essential Eight assessment services, work with Essential Eight consultants in Canberra, or compare the Essential Eight maturity levels.