Application control
Prevent execution of unapproved or malicious code, including executables, scripts, installers and compiled HTML.
The eight baseline mitigation strategies the ASD considers most effective against targeted cyber intrusion.
The Essential Eight is the ASD's prioritised list of mitigation strategies, drawn from the broader Strategies to Mitigate Cyber Security Incidents. Each strategy is measured against a three-level Maturity Model (ML1, ML2, ML3) that describes progressively stronger adversary capability being mitigated. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework (PSPF) and widely adopted by state government, local government and regulated private sector as a reasonable baseline.
Mandatory for non-corporate Commonwealth entities (via PSPF). Recommended by the ACSC for all Australian organisations and is commonly referenced by state governments, insurers and boards as a minimum expectation.
Prevent execution of unapproved or malicious code, including executables, scripts, installers and compiled HTML.
Apply patches to internet-facing applications within 48 hours; other applications within two weeks.
Disable macros for users without a demonstrated business need; block macros from the internet by default.
Configure web browsers to block Flash, ads and Java; disable untrusted Office add-ins.
Limit privileged access to those with a demonstrated need; regularly revalidate.
Apply patches for internet-facing operating systems within 48 hours; others within two weeks.
MFA for privileged users, remote access and access to important data repositories.
Daily backups of important data, retained for three months, tested and held offline or immutable.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.