
Essential 8 IT Security Review (Australia)
What is the Essential 8?
The Essential 8 is a set of eight baseline strategies recommended by ACSC (the Australian Cyber Security Centre) to help organizations protect against cyber threats. These strategies aim to prevent cyberattacks, limit their impact, and ensure quick recovery. Implementing and reporting on Essential 8 strategies is becoming increasingly important for Australian government bodies and agencies, and their suppliers.
What are the Essential 8 strategies?
The Essential 8 strategies are:
- Application Control – Prevent unauthorised software from running
- Patch Applications – Keep software updated to fix vulnerabilities
- Microsoft Office Macro Controls – Block malicious macros from external sources
- User Application Hardening – Disable unnecessary or high-risk features
- Restrict Administrative Privileges – Limit and monitor admin access
- Patch Operating Systems – Maintain secure and up-to-date systems
- Multi-Factor Authentication (MFA) – Add stronger access controls
- Daily Data Backups – Ensure recoverability in case of incidents
What does an Essential 8 Security Review include?
Step 1: Current State Assessment
Review existing controls and maturity level
Step 2: Gap Analysis
Identify gaps against Essential 8 Maturity Levels
Step 3: Risk Prioritisation
Focus on highest-risk vulnerabilities
Step 4: Remediation Roadmap
Actionable plan with timelines
Essential 8 Maturity Levels Explained
This is a brief summary of the Essential 8 maturity levels:
- Level 0 – Not implemented
- Level 1 – Basic controls
- Level 2 – Protected against common threats
- Level 3 – Advanced threat resilience
Why your organization needs an Essential 8 Assessment
- Identify gaps in your current IT security controls
- Strengthen protection against ransomware and cyber attacks
- Improve compliance with cyber security frameworks and standards
- Reduce the cost and disruption of potential security breaches
- Build a strong foundation for ISO 27001 certification
- Mandatory requirement for some government bodies and agencies
- Some government bodies and agencies require it from Suppliers
How can you get an Essential 8 Assessment?
If you have the capability, you can generally perform an Essential 8 assessment yourselves - unless there is a require for your assessment to be independent. Many businesses also struggle to perform assessments internally due to limited resources or lack of specialist expertise.
Qudos provides experienced, independent cyber security specialists who can deliver detailed
and unbiased Essential 8 assessments. Where required, we can also combine your review with a Gap Analysis against the ISO 27001 standard. See below for more details.
Can an Essential 8 Assessment be done remotely?
Yes, the choice is yours. The assessment may be performed:
- On-site
- Remotely
- Hybrid delivery options
This ensures minimal disruption while providing a comprehensive evaluation of your IT environment.
How does Essential 8 relate to ISO 27001?
The Essential 8 and ISO/IEC 27001 are closely related but serve different roles in an organization’s cybersecurity and information security strategy. While Essential 8 is a practical, prioritised set of technical controls focused specifically on mitigating common cyber threats, ISO 27001 is a comprehensive management system standard for information security (ISMS), covering governance, risk management, policies, and controls across the organization.
In simple terms: ISO 27001 = “how to systematically manage and govern all information security risks”, while Essential Eight = “what to do now to reduce cyber risk”.
The following table maps each Essential 8 control with one or more ISO 27001 controls that have primary relevance, and also some that have a supporting or indirect relationship.
| Essential 8 Control | Primary ISO 27001 Controls | Supporting ISO 27001 Controls |
|---|---|---|
| Application Control (Allowlisting) | A.8.9 Configuration management | A.8.7 Protection against malware, A.8.16 Monitoring activities |
| Patch Applications | A.8.8 Management of technical vulnerabilities | A.8.19 Software installation on operational systems, A.5.30 ICT readiness for business continuity |
| Configure Microsoft Office Macro Settings | A.8.7 Protection against malware | A.8.9 Configuration management, A.8.16 Monitoring activities |
| User Application Hardening | A.8.9 Configuration management | A.8.7 Protection against malware, A.8.21 Security of network services |
| Restrict Administrative Privileges | A.5.15 Access control, A.5.18 Access rights | A.5.16 Identity management, A.8.2 Privileged access rights |
| Patch Operating Systems | A.8.8 Management of technical vulnerabilities | A.8.19 Software installation on operational systems, A.8.9 Configuration management |
| Multi-Factor Authentication (MFA) | A.5.17 Authentication information | A.5.15 Access control, A.5.16 Identity management |
| Regular Backups | A.8.13 Information backup | A.5.30 ICT readiness for business continuity, A.5.29 Information security during disruption |
If required, Qudos can combine your review with a Gap Analysis against the ISO 27001 standard - Giving you a clear roadmap for certification and continuous improvement. Moving forward, any System development activities can also address both sets of requirements.
Frequently Asked Questions
What is the Essential Eight?
The Essential Eight is a set of cybersecurity mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to help organisations protect their systems against cyber threats and improve baseline security.
What are the Essential Eight strategies?
The Essential Eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and daily backups.
Why should IT security be reviewed regularly?
It is good practice for an organisation’s information security to be reviewed at planned intervals or when significant changes occur, ensuring ongoing effectiveness and reducing risk.
Why should an IT security review be independent?
To ensure objectivity and impartiality, IT security reviews should be performed by individuals who are independent of the area being reviewed, which can be difficult to achieve internally due to resourcing or specialist knowledge constraints.
Is an independent IT security review required for ISO 27001?
Yes. Independent reviews are required for organisations seeking ISO 27001 certification, including evaluation of technical information security controls to meet the requirements of the standard.
What does an Essential Eight IT security review include?
An Essential Eight IT security review may include assessment of IT infrastructure, security principles, antivirus and firewall systems, network security, access management, data protection and encryption, backup processes, disaster recovery, patch management, and asset management.
How can an Essential Eight IT security review be delivered?
Reviews can be performed on site, remotely, or through a combination of both depending on the organisation’s requirements.
Get a Fixed-Price Proposal
Contact Qudos Today to discuss your requirements and receive a no-obligation, fixed-price proposal for your Essential 8 IT security review.