Essential 8 IT security review

Essential 8 IT Security Review (Australia)

What is the Essential 8?

The Essential 8 is a set of eight baseline strategies recommended by ACSC (the Australian Cyber Security Centre) to help organizations protect against cyber threats. These strategies aim to prevent cyberattacks, limit their impact, and ensure quick recovery. Implementing and reporting on Essential 8 strategies is becoming increasingly important for Australian government bodies and agencies, and their suppliers.

What are the Essential 8 strategies?

The Essential 8 strategies are:

  1. Application Control – Prevent unauthorised software from running
  2. Patch Applications – Keep software updated to fix vulnerabilities
  3. Microsoft Office Macro Controls – Block malicious macros from external sources
  4. User Application Hardening – Disable unnecessary or high-risk features
  5. Restrict Administrative Privileges – Limit and monitor admin access
  6. Patch Operating Systems – Maintain secure and up-to-date systems
  7. Multi-Factor Authentication (MFA) – Add stronger access controls
  8. Daily Data Backups – Ensure recoverability in case of incidents

What does an Essential 8 Security Review include?

It typically includes infrastructure analysis, network security, access control, encryption, backups, disaster recovery, and asset management.
An Essential 8 IT Security Review is an assessment that evaluates your organisation’s alignment with the Essential 8 framework, It identifies security gaps, assigns a maturity level, and provides a clear remediation plan to reduce cyber risk. It may be broken down into the following steps:

Step 1: Current State Assessment
Review existing controls and maturity level

Step 2: Gap Analysis
Identify gaps against Essential 8 Maturity Levels

Step 3: Risk Prioritisation
Focus on highest-risk vulnerabilities

Step 4: Remediation Roadmap
Actionable plan with timelines

Essential 8 Maturity Levels Explained

This is a brief summary of the Essential 8 maturity levels:

  • Level 0 – Not implemented
  • Level 1 – Basic controls
  • Level 2 – Protected against common threats
  • Level 3 – Advanced threat resilience

Why your organization needs an Essential 8 Assessment

  • Identify gaps in your current IT security controls
  • Strengthen protection against ransomware and cyber attacks
  • Improve compliance with cyber security frameworks and standards
  • Reduce the cost and disruption of potential security breaches
  • Build a strong foundation for ISO 27001 certification
  • Mandatory requirement for some government bodies and agencies
  • Some government bodies and agencies require it from Suppliers

How can you get an Essential 8 Assessment?

If you have the capability, you can generally perform an Essential 8 assessment yourselves - unless there is a require for your assessment to be independent. Many businesses also struggle to perform assessments internally due to limited resources or lack of specialist expertise.

Qudos provides experienced, independent cyber security specialists who can deliver detailed
and unbiased Essential 8 assessments. Where required, we can also combine your review with a Gap Analysis against the ISO 27001 standard. See below for more details.

Can an Essential 8 Assessment be done remotely?

Yes, the choice is yours. The assessment may be performed:

  • On-site
  • Remotely
  • Hybrid delivery options

This ensures minimal disruption while providing a comprehensive evaluation of your IT environment.

How does Essential 8 relate to ISO 27001?

The Essential 8 and ISO/IEC 27001 are closely related but serve different roles in an organization’s cybersecurity and information security strategy. While Essential 8 is a practical, prioritised set of technical controls focused specifically on mitigating common cyber threats, ISO 27001 is a comprehensive management system standard for information security (ISMS), covering governance, risk management, policies, and controls across the organization.

In simple terms: ISO 27001 = “how to systematically manage and govern all information security risks”, while Essential Eight = “what to do now to reduce cyber risk”.

The following table maps each Essential 8 control with one or more ISO 27001 controls that have primary relevance, and also some that have a supporting or indirect relationship.

 

Essential 8 ControlPrimary ISO 27001 ControlsSupporting ISO 27001 Controls
Application Control (Allowlisting)A.8.9 Configuration managementA.8.7 Protection against malware, A.8.16 Monitoring activities
Patch ApplicationsA.8.8 Management of technical vulnerabilitiesA.8.19 Software installation on operational systems, A.5.30 ICT readiness for business continuity
Configure Microsoft Office Macro SettingsA.8.7 Protection against malwareA.8.9 Configuration management, A.8.16 Monitoring activities
User Application HardeningA.8.9 Configuration managementA.8.7 Protection against malware, A.8.21 Security of network services
Restrict Administrative PrivilegesA.5.15 Access control, A.5.18 Access rightsA.5.16 Identity management, A.8.2 Privileged access rights
Patch Operating SystemsA.8.8 Management of technical vulnerabilitiesA.8.19 Software installation on operational systems, A.8.9 Configuration management
Multi-Factor Authentication (MFA)A.5.17 Authentication informationA.5.15 Access control, A.5.16 Identity management
Regular BackupsA.8.13 Information backupA.5.30 ICT readiness for business continuity, A.5.29 Information security during disruption

 

If required, Qudos can combine your review with a Gap Analysis against the ISO 27001 standard - Giving you a clear roadmap for certification and continuous improvement. Moving forward, any System development activities can also address both sets of requirements.

Frequently Asked Questions

What is the Essential Eight?

The Essential Eight is a set of cybersecurity mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to help organisations protect their systems against cyber threats and improve baseline security.

What are the Essential Eight strategies?

The Essential Eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and daily backups.

Why should IT security be reviewed regularly?

It is good practice for an organisation’s information security to be reviewed at planned intervals or when significant changes occur, ensuring ongoing effectiveness and reducing risk.

Why should an IT security review be independent?

To ensure objectivity and impartiality, IT security reviews should be performed by individuals who are independent of the area being reviewed, which can be difficult to achieve internally due to resourcing or specialist knowledge constraints.

Is an independent IT security review required for ISO 27001?

Yes. Independent reviews are required for organisations seeking ISO 27001 certification, including evaluation of technical information security controls to meet the requirements of the standard.

What does an Essential Eight IT security review include?

An Essential Eight IT security review may include assessment of IT infrastructure, security principles, antivirus and firewall systems, network security, access management, data protection and encryption, backup processes, disaster recovery, patch management, and asset management.

How can an Essential Eight IT security review be delivered?

Reviews can be performed on site, remotely, or through a combination of both depending on the organisation’s requirements.

 

Get a Fixed-Price Proposal

Contact Qudos Today to discuss your requirements and receive a no-obligation, fixed-price proposal for your Essential 8 IT security review.