About this Framework
Maturity Level One of the ASD Essential Eight Maturity Model focuses on adversaries who are content to use commodity tradecraft that is widely available in order to gain access to, and likely control of, systems. Such adversaries look opportunistically for common weaknesses across many targets rather than investing heavily in any one of them, typically exploiting known vulnerabilities in unpatched software and weak or reused credentials. This level covers all eight mitigation strategies at their baseline: fortnightly asset discovery and vulnerability scanning, patch timeframes of two weeks to one month, multi-factor authentication on internet-facing services, restriction of administrative privileges, application control on workstations, macro and browser hardening, and tested backups.
Key Control Domains
Who Needs This?
- Australian small and medium enterprises
- Organisations beginning Essential Eight implementation
- Suppliers and contractors to Australian government
- Managed service providers and their clients
- Organisations seeking a recognised cyber security baseline
Compliance Benefits
- Mitigates the large majority of opportunistic attacks
- Recognised baseline for Australian government supply chains
- Clear, testable requirements across eight strategies
- Reduced exposure to credential theft and known exploits
- Practical starting point before uplift to higher maturity
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-1