GRCCopilot
Sign In
Australian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC)

ACSC Essential Eight - Maturity Level 2

Hardened controls, centralised logging and multi-factor authentication for privileged users

Start Assessment Create Free Account
8
Controls
107
Questions
Active
Status

About this Framework

Maturity Level Two of the ASD Essential Eight Maturity Model focuses on adversaries operating with a modest step-up in capability from Maturity Level One. They are willing to invest more time in a target, and in the effectiveness of their tools, typically using well-known tradecraft to better attempt to bypass security controls. This level tightens patch timeframes, extends multi-factor authentication to privileged users, requires application control on internet-facing servers, adds hardening of Microsoft Office, web browsers and PDF software, restricts privileged account use through jump servers and inactivity limits, and introduces centralised logging of security-relevant events.

Key Control Domains

Patch Applications
Patch Operating Systems
Multi-Factor Authentication
Restrict Administrative Privileges
Application Control
Restrict Microsoft Office Macros
User Application Hardening
Regular Backups

Who Needs This?

  • Australian government entities subject to the Protective Security Policy Framework
  • Critical infrastructure operators
  • Organisations holding sensitive or personal data at scale
  • Larger enterprises with established security operations
  • Organisations that have achieved Maturity Level One and are uplifting

Compliance Benefits

  • Resists adversaries who actively work to bypass controls
  • Centralised logging that makes intrusions detectable
  • Privileged access materially harder to abuse
  • Reduced attack surface across Office, browsers and PDF software
  • Stronger position in government and enterprise procurement

Official Reference

ACSC Essential Eight Maturity Model
https://www.cyber.gov.au

Assessment Details

Issuer / AuthorityAustralian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC)
FrameworkACSC Essential Eight - Maturity Level 2
Controls8
Questions107
StatusActive
Assessment Start05 Aug 2026

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/acsc-essential-eight-maturity-level-2

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.