Skip to content

INSIGHTS

ACSC Essential Eight audit guide for Melbourne businesses

A practical guide to preparing evidence, testing controls and planning improvements against the Essential Eight maturity model.

What is an Essential Eight assessment?

An Essential Eight assessment checks how effectively an organisation has implemented the eight mitigation strategies in the Australian Signals Directorate’s maturity model. It should test the operation of controls and collect evidence, rather than rely only on policies or verbal confirmation.

Use the current Essential Eight Assessment Process Guide and Essential Eight Maturity Model as the source of truth.

Prepare the scope before testing

Define which users, devices, servers, cloud services and administrative accounts are in scope. Record important exclusions and dependencies so the result is not mistaken for coverage of the entire business.

  • Create an inventory of in-scope systems and owners.
  • Identify privileged accounts and internet-facing systems.
  • Document outsourced services and responsibilities.
  • Select the target maturity level and record why it is appropriate.

Collect evidence for each mitigation strategy

Evidence should show both configuration and operation. Screenshots alone can become stale, so combine them with exported settings, system reports, samples and interviews with responsible staff.

  • Application control: approved applications, enforcement configuration and test results.
  • Patch applications and operating systems: asset coverage, vulnerability findings and remediation records.
  • Microsoft Office macro settings: policies, permitted exceptions and monitoring.
  • User application hardening: browser and application restrictions applied to users.
  • Restrict administrative privileges: privileged account lists, approvals and review history.
  • Multi-factor authentication: policies, authentication methods, exclusions and event logs.
  • Regular backups: protected systems, retention, separation and restoration test results.

Test effectiveness, not just settings

A configured control may still fail because of exclusions, unmanaged devices or incomplete deployment. Sample representative systems and record the method, result, exception and supporting evidence. The ASD assessment guide explains how assessors should consider implementation and effectiveness.

Turn findings into an action plan

Group findings by business risk and dependency. Assign an owner, target date and verification method to each action. Aim for a consistent maturity level across all eight strategies before moving selected controls to a higher level.

Use Southcore’s indicative Essential Eight readiness assessment ↗ or request a scoped discussion ↗. The online assessment is a planning aid and is not an ASD certification.

Essential Eight assessment questions

Is the Essential Eight mandatory for every Australian business?

No. It is a recommended baseline for organisations, while contractual, regulatory or government requirements may create specific obligations. Confirm the requirements that apply to your organisation.

Does passing a questionnaire prove compliance?

No. A reliable assessment examines implementation and evidence across the agreed scope. Automated or self-assessment results should be validated before they are used for assurance.

How often should controls be reviewed?

Review after material changes and on a schedule that reflects risk. Patch status, user access and backup restoration need recurring evidence because they change over time.

Better IT starts with a conversation.

Tell us what you need. Let’s find a way forward.