About this Framework
Maturity Level Two of the ASD Essential Eight Maturity Model focuses on adversaries operating with a modest step-up in capability from Maturity Level One. They are willing to invest more time in a target, and in the effectiveness of their tools, typically using well-known tradecraft to better attempt to bypass security controls. This level tightens patch timeframes, extends multi-factor authentication to privileged users, requires application control on internet-facing servers, adds hardening of Microsoft Office, web browsers and PDF software, restricts privileged account use through jump servers and inactivity limits, and introduces centralised logging of security-relevant events.
Key Control Domains
Who Needs This?
- Australian government entities subject to the Protective Security Policy Framework
- Critical infrastructure operators
- Organisations holding sensitive or personal data at scale
- Larger enterprises with established security operations
- Organisations that have achieved Maturity Level One and are uplifting
Compliance Benefits
- Resists adversaries who actively work to bypass controls
- Centralised logging that makes intrusions detectable
- Privileged access materially harder to abuse
- Reduced attack surface across Office, browsers and PDF software
- Stronger position in government and enterprise procurement
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-2