Essential Eight Assessment Process
A credible maturity result is based on an agreed boundary, current evidence and technical validation across all eight mitigation strategies.
The ASD Essential Eight Assessment Process Guide provides the authoritative assessment guidance. The overview below explains how its principles apply in practice without replacing the current guidance.
Define the Assessment Scope
Agree the system boundary, target maturity, users, devices, applications, services, facilities, service providers and inherited controls. The Essential Eight is assessed as a package, so selectively excluding difficult mitigation strategies does not produce a representative result.
Collect Evidence
Collect documentation, configuration data, management-platform reports, identity records, patch and vulnerability data, backup results, logs, interviews and demonstrations. Evidence quality, currency and coverage matter more than volume.
Review Each Essential Eight Mitigation Strategy
1. Application control
Review execution controls, rule maintenance, coverage and bypass resistance.
2. Patch applications
Validate application vulnerability identification, patching and treatment of unsupported software.
3. Configure Microsoft Office macro settings
Inspect macro sources, trust controls, user restrictions and monitoring.
4. User application hardening
Review security settings for web browsers, Office, PDF software and other user applications.
5. Restrict administrative privileges
Assess privileged accounts, access paths, administration practices and periodic reviews.
6. Patch operating systems
Validate operating-system vulnerability identification, patch deployment and unsupported platforms.
7. Multi-factor authentication
Assess coverage, factor strength and application to privileged and external access.
8. Regular backups
Review backup coverage, protection, retention, restoration testing and administrative access.
Conduct Technical Validation
Assessment should go beyond self-reported answers. The assessor samples systems and accounts, examines configurations and records, observes demonstrations and uses approved testing methods to confirm that controls operate across the boundary.
Determine Maturity
Results are compared with the current ASD maturity model. Requirements at higher levels are cumulative, and the outcome must reflect the assessed package rather than an average score across strategies.
Identify Gaps
Findings should identify the unmet requirement, affected scope, evidence considered and security consequence. Clear findings distinguish isolated exceptions from systemic control weaknesses.
Develop a Remediation Roadmap
Prioritise work according to risk, dependencies and operational feasibility. The roadmap should assign owners, distinguish design from implementation and include the evidence needed to demonstrate completion.
Reassess After Uplift
Reassessment validates whether remediation is implemented and effective across the relevant scope. It should test the changed control rather than rely only on a closure statement.
Plan an Essential Eight Assessment
Explore our Essential Eight assessment services, work with Essential Eight consultants in Canberra, or compare the Essential Eight maturity levels.