Lesson 5 of 10 · Track B · · Updated
The Essential Eight strategies and the evidence behind them
The Essential Eight are eight mitigation strategies from the Australian Signals Directorate: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. Each one is concrete enough that the evidence is mostly configuration and reports from your own tools.
Why these eight?
ASD describes the Essential Eight as the most effective of its Strategies to mitigate cyber security incidents, and designs them for internet-connected IT networks. They are a baseline: a short list that blocks common attack paths, with a maturity model that says how far each strategy is implemented.
Patching: applications and operating systems
Two strategies cover patching. The evidence is usually vulnerability scan results, patch reports from device management tools, and a record of how quickly security fixes were applied. Customers often ask what happens to systems that cannot be patched, so keep a list of exceptions with owners.
Identity: multi-factor authentication and administrative privileges
Multi-factor authentication evidence comes from your identity provider: which users and systems require it and which methods are allowed. Restricting administrative privileges means knowing who holds admin rights, why, and reviewing that list. User access reviews, which several platforms support, produce much of this evidence.
Hardening: application control, macros and user applications
Application control allows only approved software to run. Restricting Microsoft Office macros blocks macros unless they are needed and trusted. User application hardening configures browsers and similar applications to remove features attackers exploit. Evidence here is mostly policy settings exported from endpoint and device management tools.
Recovery: regular backups
Backups cover important data, software and configuration settings. The evidence that matters most is proof that restores were tested, not just that backup jobs ran.
Where do compliance platforms fit?
The Essential Eight evidence comes from your identity, device, patching and backup tools, so integrations matter. Of the six vendors on this site, only Vanta publishes an Essential Eight product page, with templates pre-mapped across all eight strategies; for the others we found no Essential Eight page on the pages reviewed. If you already run ISO 27001 on another platform, ask whether it can hold the Essential Eight as a custom framework and who maintains the mapping.
How should you organise the evidence?
Keep one folder or control record per strategy, with the report, the date it was produced, the system it covers and the person who reviewed it. Note exceptions next to the evidence rather than in a separate document, because assessors and customers will ask about them together. Refresh the evidence on a schedule: a patch report from six months ago says little about today. If you run ISO 27001 as well, store the Essential Eight evidence against the matching ISO 27001 controls so that one review serves both.