Home / Rules / Essential Eight Maturity Model
Essential Eight Maturity Model: the rules AI agent steps rest on
- Edition
- Essential Eight Maturity Model, November 2023, with the Essential Eight to ISM mapping (December 2023)
- Checked current
- 2026-09-30
- Official source
- https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model
The Essential Eight is cited only on the root-cause step of a breach or ransomware chain: which mitigation strategy and ISM control at the target maturity level failed. It never decides a notification step.
| Rule | Our statement | Steps that cite it |
|---|---|---|
| Essential Eight, Multi-factor authentication, ISM-1504 (Maturity Level One) | Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data. Required at Maturity Levels One, Two and Three of the Multi-factor authentication mitigation strategy (Appendices A, B and C); ISM control ISM-1504 in ASD's Essential Eight to ISM mapping (December 2023). | KC-02 S7 Which Essential Eight control failed? |
| Essential Eight, Regular backups, ISM-1707 (Maturity Level Two) | Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups. Required at Maturity Levels Two and Three of the Regular backups mitigation strategy (Appendices B and C); ISM control ISM-1707 in ASD's Essential Eight to ISM mapping (December 2023). | KC-04 S7 Which Essential Eight control failed? |