Skip to content
Menu

Essential Eight self-assessment checklist

Your maturity level, in eight questions.

The Essential Eight is the Australian Government’s list of eight controls that stop most cyber attacks. Answer one question for each control. You get your estimated maturity level and a PDF for your board, broker or auditor.

A tablet showing a form with rows of tick boxes, beside a USB security key, a pen, a navy binder and a coffee on an office desk.

At a glance

Questions
Eight, one for each control
Time
About 10 minutes
You get
Your level, ML0 to ML3, and a PDF
Your data
Stays in your browser. No email

Essential Eight questions in plain English

Answer for what is in place today.

Each question tells you what the control is before it asks. If you do not know an answer, pick “Not sure”. Open “Help me answer” for the question to ask your IT provider.

Question 1 of 8: Application control

Application control lets only approved programs run on your computers. Windows blocks every other program.

Why it matters. Most malware is a program that must run to do damage. If it cannot run, it cannot lock your files or steal passwords. Read the guide →

Which statement is true for your staff computers?

Help me answer

How to check

Stopping staff from installing software is not application control. Application control stops a program from running, even when nobody installed it.

Ask your IT provider

“Do we use application control, such as WDAC or AppLocker, on our computers?”

Words used here

Allowlist:
The list of programs that are approved to run.
WDAC and AppLocker:
The two Windows features that do application control.
Question 2 of 8: Patch applications

Software companies release security updates to fix flaws. Patching means you install these updates on a schedule.

Why it matters. Attackers use flaws that are already public. Until you install the update, the flaw stays open. Read the guide →

How fast do security updates go on to web browsers, Microsoft Office, email and PDF apps?

Different question

This question is about apps only. Question 6 asks the same thing about Windows, macOS, servers and network devices.

Help me answer

How to check

Look at one staff computer. Open the browser and Microsoft Office and check for updates. If updates are waiting, or the version is months old, the answer is probably “Nobody checks”.

Ask your IT provider

“How many days after release do our app updates go on, and how do you confirm that they installed?”

Words used here

Patch:
A security update from the software company.
Unsupported app:
An app that the vendor no longer updates. Its flaws will never be fixed.
Question 3 of 8: Configure Microsoft Office macro settings

A macro is a small program inside a Word or Excel file. Attackers hide harmful macros in files that look like invoices or quotes.

Why it matters. Many ransomware attacks start with a macro in an email attachment. If the macro cannot run, the attack stops. Read the guide →

Who can run macros in Microsoft Office files?

Help me answer

How to check

If nobody in your business uses macros, the settings can turn them off for everyone. Most small businesses can do this.

Ask your IT provider

“Are Office macros blocked for staff who do not need them, and for files from the internet?”

Words used here

Signed macro:
A macro with a digital signature that shows who made it and that nobody changed it.
Trusted Location:
An approved folder. Only macros in that folder can run.
Question 4 of 8: User application hardening

Hardening means you turn off app features that staff do not use but attackers do. This question is about web browsers, Microsoft Office and PDF readers.

Why it matters. Old features, such as Java in a browser, give attackers a way in. When these features are off, that way in is closed. Read the guide →

Have your web browsers, Microsoft Office and PDF readers been set up to be safer than their default settings?

Help me answer

How to check

A new computer uses default settings. If nobody applied a security policy through Microsoft Intune or Group Policy, the answer is “No”.

Ask your IT provider

“Do we apply ASD’s hardening guidance to our browsers, Office and PDF apps through Intune or Group Policy?”

Words used here

Intune and Group Policy:
Microsoft tools that push the same settings to every computer.
Constrained Language Mode:
A PowerShell setting that stops scripts from doing dangerous things.
Question 5 of 8: Restrict administrative privileges

An admin account can install software, change settings and create users. An attacker with an admin account can control your whole network.

Why it matters. Malware gets the same rights as the account that runs it. When staff work without admin rights, malware can do less damage. Read the guide →

Who has admin rights, and how do they use them?

Help me answer

How to check

On a staff computer, right-click a program and choose “Run as administrator”. If Windows asks for an admin password, that account does not have admin rights.

Ask your IT provider

“Who has admin rights on our computers and in Microsoft 365, and are those accounts blocked from email and the web?”

Words used here

Admin account:
An account with the rights to change anything on a computer or network.
Just-in-time access:
Admin rights that are given for one task and then removed automatically.
Question 6 of 8: Patch operating systems

The operating system is the main software on a device, such as Windows or macOS. Routers, firewalls and switches also have one, called firmware.

Why it matters. Every app runs on the operating system. A flaw in the operating system puts everything on that device at risk. Read the guide →

How fast do security updates go on to computers, servers and network devices?

Different question

This question is about operating systems, not apps. Question 2 asked about browsers, Office and PDF apps. Many businesses give different answers to the two questions.

Help me answer

How to check

Windows 10 and Windows Server 2012 no longer get security updates. If any of your devices use them, the answer is “Nobody checks” or “Within one month”.

Ask your IT provider

“How many days after release do Windows, server and firewall updates go on, and which devices use versions that no longer get updates?”

Words used here

Firmware:
The operating system inside a router, firewall, switch or other network device.
End of life:
The date after which the vendor stops sending security updates.
Question 7 of 8: Multi-factor authentication

Multi-factor authentication (MFA) asks for a second proof when someone signs in. The second proof is usually a phone app, a passkey or a security key.

Why it matters. Attackers steal passwords with fake sign-in pages. With MFA, a stolen password alone does not let them in. Read the guide →

Where do your staff use MFA?

Help me answer

How to check

If staff type a six-digit code or tap “Approve” on their phone, you have MFA. It is not phishing-resistant, because a fake sign-in page can pass the code on.

Ask your IT provider

“Which of our systems use MFA, and do any of them use passkeys, security keys or Windows Hello for Business?”

Words used here

Phishing-resistant MFA:
MFA that a fake sign-in page cannot copy. Examples are passkeys, security keys and Windows Hello for Business.
Security key:
A small USB or NFC device that proves who you are when you sign in.
Question 8 of 8: Regular backups

A backup is a copy of your data, apps and settings. You use it to recover after ransomware, a hardware failure or a mistake.

Why it matters. Ransomware tries to delete your backups first. A backup that attackers cannot change, and that you have restored in a test, is how you recover. Read the guide →

How are your backups kept and tested?

Help me answer

How to check

Ask when someone last restored a file or a whole system from backup to prove that it works. If nobody can give you a date, the answer is the first one.

Ask your IT provider

“When did we last test a full restore, and can an admin account delete our backups?”

Words used here

Restore test:
You recover data from a backup on purpose, to prove that the backup works.
Keep period:
How long each backup is kept before it is deleted. Also called the retention period.

8 questions left.

How Essential Eight maturity is scored

The same rules an auditor uses, without the evidence.

The Essential Eight is a set of eight security controls from the Australian Signals Directorate (ASD). ASD measures each control at a maturity level from ML0 to ML3. This check uses ASD’s November 2023 model.

  1. 01

    Answer for today

    Pick the answer that is true now, not the answer that you plan for. If a control is only on some computers, pick the lower answer.

  2. 02

    Your lowest control sets your level

    Your overall level is your lowest control, not the average. If seven controls are at ML2 and one is at ML0, you are at ML0. ASD scores the Essential Eight this way.

  3. 03

    Take the PDF with you

    Download your level and a result for each control. Give it to your board, your insurance broker or your auditor. Your device makes the PDF from your answers.

  4. 04

    Evidence is the real test

    An auditor, insurer or regulator checks documents and tests the controls. They do not use your own answers, so their result can be lower than this one.

What is the Essential Eight?
Does anything I enter leave my browser?
Is this an official Essential Eight assessment?
I do not know some of the answers. What do I do?
Why is my overall level my lowest score?
Which maturity level should we aim for?
We scored ML0. Where do we start?

Close the gap to the next level.

Book a free cyber risk review with a Perth engineer. Bring your result. You get the controls to fix first and what it takes to move up a level.

Or call (08) 9467 2269

What you are working towards
Staff

A Perth engineer, not a salesperson, replies within one business day.

We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.