Back to blog
Checklists

Essential Eight evidence checklist: what to have ready for each strategy

A strategy-by-strategy list of the artefacts an assessor will ask for, what makes each one sufficient, and the evidence gaps that most often turn a working control into a failed requirement.
GRC Copilot Team
Essential Eight evidence checklist: what to have ready for each strategy

Roughly half of Essential Eight failures are evidence failures, not control failures. The control works; nobody can prove it worked last month. This checklist is what to have in the folder before an assessment starts.

One rule runs through all of it: point-in-time evidence is weak evidence. A screenshot proves a setting today. Assessors want to see the requirement met over a period.

Cross-cutting evidence

  • Asset inventory, current, with the basis on which it is maintained. Almost every requirement is measured against it — coverage is meaningless without a denominator.
  • Network and system architecture showing internet-facing versus internal, and any segmented or legacy zones.
  • Scope statement naming what is included, and explicitly what is excluded and why.
  • Change records for the period, so configuration can be tied to dates.

1 and 2. Patch applications and operating systems

  • Automated asset discovery schedule and output showing at least fortnightly runs.
  • Vulnerability scanner configuration proving an up-to-date vulnerability database.
  • Scan schedules matching the required cadence per asset class — daily for internet-facing, weekly or fortnightly as applicable.
  • Patch age report over several months, showing time from vendor release to deployment against the required window.
  • Records of expedited patching where an exploit existed, with the decision recorded.
  • End-of-life register showing unsupported software and operating systems removed or replaced, with dates.

3. Multi-factor authentication

  • Conditional access or equivalent policy exports showing enforcement, not availability.
  • List of internet-facing services you operate, each mapped to its MFA status.
  • List of third-party services holding your data, each mapped to MFA status and whether the data is sensitive.
  • Evidence of the factor types in use, sufficient to show the combination requirement is met.
  • From Level Two: central MFA logs. From Level Three: evidence those logs cannot be modified or deleted.

Attach evidence to the requirement it satisfies

GRC Copilot ships the Essential Eight as four assessments with evidence upload against each individual requirement, so the folder assembles itself as you work.

4. Restrict administrative privileges

  • Privileged account inventory, including service accounts, break glass accounts and local administrators.
  • Access request and validation records showing privilege was approved when first requested.
  • Evidence that privileged accounts cannot reach internet, email and web services — enforced, not policy text.
  • Evidence of separate privileged and unprivileged environments and the logon restrictions between them.
  • From Level Two: annual revalidation records, 45-day inactivity disablement, jump server configuration, and central logs of privileged access and group management.

5. Application control

  • Ruleset export covering executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets.
  • Proof of enforcement mode rather than audit mode.
  • Coverage report against the asset inventory, as a percentage with the gap named.
  • Exception register with business justification, approver and expiry.
  • From Level Two: blocklist implementation, annual ruleset validation record, central logs of allowed and blocked executions.

6. Restrict Microsoft Office macros

  • Policy export showing macros disabled except for users with a demonstrated business requirement.
  • The register of that business requirement — who has macros enabled and why. This is the artefact most often missing entirely.
  • Evidence macros from the internet are blocked and antivirus scanning is enabled.
  • Evidence users cannot change macro settings.

7. User application hardening

  • Browser configuration exports covering Java, web advertisements and Internet Explorer 11.
  • Evidence users cannot change browser security settings.
  • From Level Two: hardening baselines applied to browsers, Office and PDF software, with the guidance they follow named, plus the behavioural restrictions on Office and PDF child processes.

8. Regular backups

  • Backup schedule and retention configuration tied to a stated business continuity requirement.
  • Evidence of synchronisation enabling restoration to a common point in time.
  • A dated restoration test record from a disaster recovery exercise, including what was restored and whether it succeeded.
  • Access control configuration on the backup system showing unprivileged accounts cannot access, modify or delete backups.
  • From Level Two: the same restriction for privileged accounts other than backup administrators.

The five gaps that cost the most

  1. No patch age report over time — only a current console view.
  2. No macro business-requirement register.
  3. No restoration test record, despite backups running reliably.
  4. Application control coverage stated as "deployed" with no percentage against inventory.
  5. Third-party services never enumerated, so MFA scope cannot be demonstrated.

Frequently asked questions

How far back should evidence go?

Enough to show the requirement was met consistently rather than configured recently. Three to twelve months is the usual expectation depending on the requirement; patch timeframes in particular need a run of data.

Are screenshots acceptable?

For configuration state, often yes, provided they are dated and identify the system. For anything with a timeframe or a cadence, a report or export is far stronger, because a screenshot cannot show consistency.

What if a control is delivered by a managed service provider?

The requirement still applies to you, and so does the evidence. Get the reports contractually, on a schedule, in a form you can hand to an assessor — asking for them the week before an assessment rarely goes well.

Do we need evidence for strategies we consider not applicable?

Yes, and more of it. Non-applicability needs a documented, defensible rationale tied to the environment. Assessors treat unexplained exclusions as gaps.

Key takeaways

  • Point-in-time screenshots do not evidence a timeframe requirement.
  • Coverage needs a denominator, which means the asset inventory underpins everything.
  • The macro business-requirement register and the restoration test record are the two most commonly absent artefacts.
  • Evidence delivered by a provider must be contracted for in advance.
#essential-eight #evidence #checklist #acsc #australia #assessment-preparation