CyberFrame structures Essential Eight assessments around the eight mitigation strategies and three maturity levels. Each control is evaluated per asset group at the target maturity level, with structured test methods guiding every evaluation and reports aligned to ASD requirements.
Mitigation Strategies
Target Maturity
66% of strategies at ML2 or above
The Essential Eight is a set of baseline mitigation strategies published by the Australian Cyber Security Centre (ACSC) to help organisations protect themselves against cyber threats. It builds on the broader Information Security Manual (ISM) by focusing on eight specific strategies that address the most common attack vectors.
The eight strategies are: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Each strategy is assessed at one of four maturity levels (ML0 through ML3), with ML3 representing the most mature implementation.
An Essential Eight assessment evaluates an organisation's implementation of each strategy against the target maturity level. This involves reviewing controls per asset group, gathering evidence of implementation, and determining whether the organisation meets the requirements for each level. The assessment is incremental: you assess against ML1, then ML2, then ML3.
Essential Eight assessments are increasingly required for Australian Government agencies and are widely adopted by private sector organisations as a practical cyber security baseline. The framework is regularly updated by ACSC to reflect evolving threats.
Essential Eight assessments require evaluating controls across eight strategies at specific maturity levels, each with different requirements per asset group. Tracking which controls apply at which maturity level, collecting evidence per strategy, and reporting maturity progression is complex without a platform that understands the E8 structure natively.
All eight strategies structured with their own control sets, maturity requirements, and evaluation criteria. Navigate by strategy, by maturity level, or by asset group depending on how your assessment is structured.
Evaluate controls at the target maturity level per asset group. ML1, ML2, and ML3 each have distinct requirements. CyberFrame scopes the applicable controls to the target level so assessors evaluate what is relevant, not everything.
Essential Eight controls are drawn from the ISM. CyberFrame maintains the mapping between strategies, maturity levels, and ISM controls so assessors work with the correct control set for each strategy and tier.
Structured test methods tailored to each maturity level guide assessors through the evaluation of every control-asset pairing. Assessment techniques are categorised and evidence requirements are clear for each level.
A dedicated Essential Eight assessment workflow defines the phases, objectives, and activities. Report templates are aligned to E8 output requirements so the deliverable structure matches what is expected.
Evidence is linked directly to the controls, strategies, and maturity levels it supports. Assessors can see which strategies have sufficient evidence and which need further collection, all within the workspace.
See how CyberFrame gives your Essential Eight assessment the depth, tracking, and reporting that maturity-based evaluation demands.