The Australian Signals Directorate (ASD) has developed prioritised mitigation strategies to help organisations protect themselves against various cyberthreats. The most effective of these mitigation strategies are the Essential Eight (E8).
Application Control
Patch Applications
Configure Microsoft Office Macro Settings
User Application Hardening
Restrict Administrative Privileges
Patch Operating Systems
Multi-Factor Authentication (MFA)
Regular Backups
Alongside the E8 mitigation strategies are a series of maturity levels that can be used to guide an organisation’s implementation of the E8.
The maturity levels also provide a standard against which an organisation can be measured to ensure they have an appropriate baseline of cyber security controls.
The concept of Essential 8 is relatively straightforward however, implementation of the controls, drafting of the associated documentation and collection of audit trail evidence can become a complex undertaking leading to unexpected gaps that can be a barrier to compliance.
Kaon Security’s E8 readiness service is designed as a precursor to a formal E8 assessment, the collaborative workshop led approach removes any ambiguity about the E8 requirements and lays the foundation for a successful E8 assessment.
The readiness review is based on information collected during a series of workshops, and any supplementary evidence provided by the organisation to document the current state of their cyber security controls against the appropriate maturity level.
Our senior consultant team work with you to identify gaps and will provide actionable recommendations to enhance overall compliance and maturity.
Identify any gaps to be closed in advance of a full assessment
Reduce the time and effort to complete a full assessment
Improve the likelihood of a successful assessment result in line with the organisation’s expectations
3 workshops
Review existing documentation and assess alignment with ASD E8 MLx
Perform a gap analysis
Draft a Readiness Review Report
An Essential 8 assessment is a comprehensive technical examination of your security controls and documentation.
The assessment is performed in accordance with the published ASD maturity levels assessment guidance and is a binary exercise to clearly identify exactly where the organisation does or does not meet the requirements of the ASD E8.
Our senior consultant team work with you to collect evidence and our technical consultant team will perform the technical verification steps to comprehensively prove compliance.
Technical verification of the effectiveness of the implemented controls
Understand the organisation’s exact compliance status with the E8
Identify areas for improvement before moving to the next maturity level
Access to an evidence submission portal for use during the assessment
Report on ASD maturity level including results of technical verification
Slide deck of results for internal presentation