ESSENTIAL 8ASD-aligned · ML1 → ML3 evidence 

Essential 8 maturity, evidenced.

Cyber Aware's Gap Assessment maps directly to all three Essential 8 maturity levels. Evidence is collected automatically as your client's learners complete training and acknowledgements - branded under your name, exported as one audit-ready PDF.

WHAT IS IT?

Australia's baseline cyber framework.

The Essential 8 is the ASD's mitigation strategy framework - eight controls that prevent or limit the impact of the most common cyber-attacks. Required for federal contracts. Recommended for every Australian business.

1

Application control

Restrict execution of malicious code. The most effective mitigation across the framework.

2

Patch applications

Mitigate vulnerabilities in applications. Apply patches within 48h for critical CVEs.

3

M365 macro settings

Block macros from the internet to reduce a major malware delivery vector.

4

User application hardening

Configure browsers and PDF readers to block ads, Flash and Java by default.

5

Restrict admin privileges

Privileged operations only from privileged accounts. Periodic re-validation required.

6

Patch operating systems

Apply OS patches within 48h. Use the latest supported version of each OS.

7

Multi-factor authentication

MFA on every internet-facing service and privileged action. Hardware tokens preferred.

8

Regular backups

Daily backups, restore-tested quarterly, with offline copies held offsite.

HOW WE MAP

From ML0 to ML3 - covered by Cyber Aware.

Cyber Aware's Gap Assessment is pre-mapped to all three Essential 8 maturity levels. Evidence is collected automatically as learners complete training and acknowledgements.

Control
ML1
ML2
ML3
Application control
Patch applications
M365 macro settings
User application hardening
Restrict admin privileges
Patch operating systems
Multi-factor authentication
Regular backups
EVIDENCE COLLECTION

Audit-ready, automatically.

// USER TRAINING
Application control awareness, macro security, password practices, MFA usage. Every completion timestamped and assigned to a learner with E8 control mapping.
// PHISHING METRICS
Click-through rates, report rates, credential-compromise rates across all simulated campaigns - used as MFA-readiness signal.
// ASSESSMENT ARTIFACTS
Maturity-level question responses, attestations from administrators, organisational scope statements - exported as one branded PDF per audit.
// POLICY ACKNOWLEDGEMENTS
Acceptable Use Policy, BYOD Policy, Password Policy. Every learner attests, every attestation logged with timestamp and IP.
Get audit-ready

One platform.
Every framework.

Spin up a fully branded compliance assessment portal under your name. Evidence collected automatically as learners complete training.