ASD / ACSC — Essential Eight ↗
Use the current maturity model and assessment guidance for an evidence-based uplift programme. It is a baseline, not a complete security programme.
Checked 11 October 2026 · Source: ASD / ACSC
RESOURCES / CHECKED 11 OCTOBER 2026
Authoritative guidance for planning and governance. Check the latest requirements before relying on them.

Use the current maturity model and assessment guidance for an evidence-based uplift programme. It is a baseline, not a complete security programme.
Checked 11 October 2026 · Source: ASD / ACSC
The APPs govern information handling for entities within their scope. Review security, disposal and overseas disclosure requirements relevant to your data.
Checked 11 October 2026 · Source: OAIC
Covered entities must assess suspected eligible breaches and notify where required. Serious harm, remedial action and exceptions matter.
Checked 11 October 2026 · Source: OAIC
Released 22 November 2023, the 2023–2030 strategy sets national policy direction. It does not certify a business or replace law.
Checked 11 October 2026 · Source: Home Affairs
Review information security capability, testing and notification duties for APRA-regulated entities.
Checked 11 October 2026 · Source: APRA
SOCI duties depend on asset class and the entity’s role. Confirm reporting and risk management applicability with qualified advisers.
Checked 11 October 2026 · Source: CISC
Agree an assessment boundary and target maturity. Record control evidence, distinguish exceptions from gaps and sequence dependencies. Review the ASD model before reassessment.
Find externally shared repositories, review guests and link expiry, confirm audit retention and test revocation. Check overseas disclosure and provider terms where relevant.
Choose a realistic compromise scenario. Test authority, evidence preservation, communications and restoration. Identify notification questions for legal review.
A CLEARER NEXT STEP