RoutineMetric

ASD Essential Eight Maturity & Compliance Gap Calculator

Assess your organization's cybersecurity posture against the Australian Signals Directorate (ASD) Essential Eight guidelines. Identify Maturity Levels (0 to 3), calculate gaps based on progressive alignment rules, and export compliance remediation SLA reports.

Maturity Checklist

Complete checklists across the 8 mitigation strategies.

Application Control

Prevent unauthorized or malicious software from executing on workstations and servers.

Remediation & Compliance Roadmap

Set Target Alignment

Select target ASD level to generate gaps analysis.

Prioritized Gaps Checklist (8)
Application ControlLvl 0 → Lvl 2

Implement Level 1 controls: Workstation Control (Application control is implemented on all workstations to restrict execution of executables, software libraries (DLLs), scripts, and installers to an approved set.)

Patch ApplicationsLvl 0 → Lvl 2

Implement Level 1 controls: 2-Week Remediation Cycle (Patches or security updates for extreme/high risk vulnerabilities in applications (e.g. web browsers, PDF readers, office suites) are applied within 14 days of release.)

Configure Microsoft Office Macro SettingsLvl 0 → Lvl 2

Implement Level 1 controls: Need-based Access & Internet Block (Microsoft Office macros are disabled for users without a verified business need. Macros sourced from the internet are blocked from running.)

User Application HardeningLvl 0 → Lvl 2

Implement Level 1 controls: Disable Legacy Web Plugins (Web browsers are configured to block Java and legacy web plugins. Browser settings are locked against unauthorized user modification.)

Restrict Administrative PrivilegesLvl 0 → Lvl 2

Implement Level 1 controls: Need-based Restricting & Account Separation (Admin privileges are limited to required staff. System administrators use separate, dedicated standard accounts for daily tasks like email and web browsing.)

Patch Operating SystemsLvl 0 → Lvl 2

Implement Level 1 controls: 2-Week OS Patching Cycle (Extreme/high risk vulnerabilities in operating systems are patched within 14 days of release. Legacy or unsupported OS platforms are retired or isolated.)

Multi-factor AuthenticationLvl 0 → Lvl 2

Implement Level 1 controls: Remote Access & Cloud MFA (MFA is implemented and enforced for all remote access systems (VPN, SSH, RDP) and cloud/SaaS software suites (Office 365, AWS, GCP, Salesforce).)

Regular BackupsLvl 0 → Lvl 2

Implement Level 1 controls: Weekly Backup & 3-Month Retention (Backups of critical data, databases, and metadata are performed at least weekly and retained for a minimum of 3 months.)

Audit Status

Maturity Dashboard

Overall Maturity LevelLevel 0Level 1 Criteria Unmet
Incremental Progress0.00 / 3.00 Avg

*Note: While overall maturity is limited by your weakest strategy, the average maturity measures incremental enhancements.

Strategies Score Matrix
Application Control
Lvl 0
Patch Applications
Lvl 0
Configure Microsoft Office Macro Settings
Lvl 0
User Application Hardening
Lvl 0
Restrict Administrative Privileges
Lvl 0
Patch Operating Systems
Lvl 0
Multi-factor Authentication
Lvl 0
Regular Backups
Lvl 0

Essential Eight Auditing Tips

The Weaker-Link Policy: Official ASD audits do not recognize fractional averages. Your certified level is determined exclusively by the lowest level achieved in any singular strategy.

Progressive Alignment: Implementing Level 3 requirements for a strategy without resolving missing Level 1 and 2 elements is recognized as Level 0 because security dependencies cascade upwards.

Ransomware Shielding: Organizations prioritizing ransomware defense should focus heaviest on Application Control, Restricting Privileges, and Regular Backups first.

Advertisement
Bottom Banner Ad (728x90)

Understanding the ASD Essential Eight Maturity Framework

The Australian Signals Directorate (ASD) developed the Essential Eight as a baseline set of cybersecurity mitigation strategies to help organizations protect themselves from cyber attacks. Although designed originally for government entities, it has transitioned globally into a gold standard for private enterprise, critical infrastructure, and security-mature organizations.

The progressive Maturity Level Philosophy

Unlike frameworks that evaluate general maturity percentages, the Essential Eight demands progressive implementation. To achieve Maturity Level 1, 2, or 3, an organization must implement every requirement associated with that level. Because security dependencies are hierarchical (for example, applying application restrictions is moot if administrative privileges are unchecked), skipping items or executing partial components renders that strategy at Maturity Level 0.

The Eight Mitigation Strategies Defined

The strategies are grouped into three primary security objectives:

  • Prevent Cyber Attacks: Application Control, Patch Applications, Configure Microsoft Office Macro Settings, and User Application Hardening. These controls stop malicious payloads from initiating.
  • Limit Impact: Restrict Administrative Privileges and Patch Operating Systems. These limit lateral movement and secure administrative credentials.
  • Data Availability: Multi-factor Authentication and Regular Backups. These ensure access is guarded and systems can be successfully reconstructed.

How to Audit and Remediation Planning with This Tool

To maintain an audit-ready compliance posture:

  1. Audit your systems to complete the checklists honestly for each strategy.
  2. Evaluate your Overall Strict Maturity Level. If it is Level 0, locate which specific strategies are dropping your rating.
  3. Use the Remediation Roadmap to prioritize SLA plans. For instance, elevating a single strategy from Level 0 to Level 2 can immediately raise your organization's certified posture.
  4. Generate and save the Contemporaneous Audit Memorandum (.MD) file as evidence for board reporting and internal security validation.
Disclaimer: This online planning utility is for internal risk modeling, security training, and strategic simulation purposes only. ASD certification must be verified by a registered IRAP (Information Security Registered Assessors Program) assessor or qualified cyber security auditor.
GustoVerified Payroll Partner
Payroll & S-Corp
3 Months Free + $100 Visa Card

Run IRS-Compliant S-Corp & Small Business Payroll

Automate officer reasonable compensation, federal tax withholdings, and quarterly W-2/941 filings with zero manual paperwork.

Discussion & Comments

Join the conversation, ask questions, or share feedback.

Advertisement