← Back to Library
ACSC L1

ACSC L1 (v2022)

Full Name: Australian Cyber Security Centre (ACSC) Essential Eight - Level 1

Acronym: ACSC L1

Type: Cyber Hygiene Standard

Organization: Australian Cyber Security Centre

Version: 2022

Year Published: 2022

Popularity: Moderate

Overview of ACSC Essential Eight Level 1

The ACSC Essential Eight Maturity Level 1 represents the baseline cybersecurity posture recommended by the Australian Cyber Security Centre for organizations seeking to protect against common cyber threats. Released as part of the 2022 Maturity Model update, Level 1 focuses on implementing eight essential mitigation strategies with foundational controls that prevent approximately 85% of targeted cyber intrusions. Level 1 is designed for organizations taking their first steps toward mature cybersecurity, with partially implemented controls across all eight strategies.

Originally developed by the Australian Signals Directorate (ASD) based on analysis of actual cyber incidents, the Essential Eight framework prioritizes the most effective mitigation strategies that deliver maximum risk reduction. The 2022 update refined requirements to address evolving threats including ransomware, supply chain compromises, and sophisticated phishing campaigns. Level 1 provides pragmatic, achievable controls suitable for small to medium organizations or as the foundation for larger enterprises advancing to higher maturity levels.

The Eight Essential Mitigation Strategies

At Maturity Level 1, organizations implement partial controls for each of the eight strategies. These strategies target the most common attack vectors observed by the ACSC in responding to cyber incidents affecting Australian organizations.

1. Application Control

Application control prevents execution of unapproved or malicious programs on workstations. At Level 1, organizations implement application control on workstations (not servers) to allow only approved and trusted programs to execute. This blocks malware execution even if users download malicious software through phishing or web browsing. Level 1 focuses on preventing execution from standard user profile locations and temporary folders where malware typically attempts to run. Organizations commonly use Microsoft AppLocker, Windows Defender Application Control (WDAC), or third-party application whitelisting solutions.

2. Patch Applications

Vulnerability exploitation remains a primary attack vector for cyber criminals. Level 1 requires patching security vulnerabilities in applications within two weeks when exploits are publicly available or actively exploited in the wild. Priority applications include internet-facing software such as web browsers, PDF viewers, Microsoft Office, Adobe products, Java, and other applications with internet connectivity. Organizations should maintain inventories of installed applications, subscribe to vendor security notifications, and implement testing and deployment processes enabling rapid patching when critical vulnerabilities emerge.

3. Configure Microsoft Office Macro Settings

Malicious macros embedded in Microsoft Office documents represent a common malware delivery mechanism used in phishing campaigns. Level 1 requires blocking macros from the internet and only allowing macros from trusted locations to execute. This prevents macro-based malware commonly delivered via email attachments. Organizations should configure Group Policy or endpoint management tools to enforce macro settings across all workstations, establish trusted locations for legitimate business macros, and train users to recognize suspicious Office documents requesting macro enablement.

4. User Application Hardening

Application hardening reduces attack surface by disabling unnecessary features and plugins that attackers exploit. Level 1 requires blocking web advertisements, disabling untrusted Microsoft Office add-ins, blocking or disabling Java from the internet, and disabling unneeded features in PDF viewers. These technologies have historically contained numerous vulnerabilities that attackers weaponize. Organizations should configure web browsers securely, uninstall unnecessary browser plugins, and use centralized browser management to enforce consistent security configurations across the enterprise.

5. Restrict Administrative Privileges

Administrative privileges provide broad system access that attackers abuse to install malware, modify security settings, and move laterally across networks. Level 1 requires restricting administrative privileges to operating systems and applications based on user duties. Regular users should not have administrative rights on their workstations. Organizations should implement privileged access management practices, use separate privileged accounts for administrative tasks, disable local administrator accounts on workstations, and validate privileged users annually to ensure appropriate access levels are maintained.

6. Patch Operating Systems

Similar to application patching, operating system vulnerabilities must be addressed promptly to prevent exploitation. Level 1 requires patching security vulnerabilities in operating systems of workstations, servers, and network devices within one month when exploits are publicly available or being actively exploited. Organizations should implement automated patch management systems, maintain current operating system versions that still receive security updates from vendors, and establish testing procedures to validate patches before widespread deployment to production systems.

7. Multi-Factor Authentication

Multi-factor authentication (MFA) significantly reduces account compromise risk by requiring users to provide two or more authentication factors. Level 1 requires MFA for remote access solutions including VPNs, remote desktop services, and web-based remote access. This ensures attackers cannot gain remote access using stolen credentials alone. Organizations should implement MFA using authenticator apps, hardware tokens, or SMS-based verification. While SMS is less secure than other methods, Level 1 accepts any MFA implementation. MFA should be enforced for all remote access pathways without exception.

8. Daily Backups

Effective backups enable recovery from ransomware attacks, destructive malware, hardware failures, and human errors. Level 1 requires daily backups of important data, software, and configuration settings. Backups should be stored offline or in separate environments to prevent attackers from deleting them during ransomware attacks—a common tactic used by sophisticated ransomware operators. Organizations should test backup restoration procedures at least quarterly, maintain backup retention appropriate to business needs, and ensure backups include all critical systems and data necessary for business continuity.

Implementation Strategies and Best Practices

Successfully implementing Essential Eight Level 1 requires structured planning, executive support, and phased deployment. Organizations should begin with comprehensive gap assessments using the ACSC's Essential Eight Maturity Model self-assessment template to identify current maturity levels for each strategy and prioritize remediation efforts based on risk and feasibility.

Prioritize Based on Current Threat Landscape: While all eight strategies are important, organizations with limited resources should prioritize those providing the greatest immediate risk reduction. Application control, patching applications, and restricting administrative privileges typically provide the highest impact. The ACSC recommends focusing on preventing malware delivery and execution as first priorities, as these controls stop attacks before they can establish footholds in organizational networks.

Leverage Existing Technology Investments: Many organizations already possess tools capable of supporting Essential Eight controls without new purchases. Windows includes AppLocker for application control, Group Policy for macro settings and application hardening, and Windows Update for patching. Maximizing existing capabilities before purchasing new solutions reduces costs and implementation complexity. Cloud providers often include security capabilities that can be configured to support Essential Eight requirements.

Start with Pilot Groups: Rather than attempting enterprise-wide deployment immediately, test implementations with pilot user groups. This allows identification and resolution of technical issues, business process impacts, and user training needs before broad rollout. IT departments and security teams often make effective pilot groups as they can troubleshoot issues and refine processes before impacting broader user populations. Document lessons learned during pilots to improve subsequent deployment phases.

Plan Progressive Maturation: Level 1 represents a baseline, not a destination. Organizations should develop roadmaps for advancing to Level 2 and ultimately Level 3 over 1-3 years based on risk appetite, regulatory requirements, and resource availability. Each maturity level builds upon the previous level with more comprehensive and automated controls. Planning multi-year maturation helps secure sustained funding and executive commitment for cybersecurity improvement programs.

Framework Applicability and Adoption

The Essential Eight Level 1 is applicable to all Australian organizations, from small businesses to large enterprises and government agencies. Small and medium-sized businesses can use Level 1 as their primary cybersecurity framework, while larger organizations typically view Level 1 as the minimum baseline before advancing to Level 2 or Level 3 based on their threat environment and risk profile.

While the Essential Eight is mandated for Australian Government agencies, it remains voluntary for private sector organizations. However, it serves as best practice guidance that aligns with various Australian regulatory frameworks including the Privacy Act, the Security of Critical Infrastructure Act (SOCI Act), and industry-specific regulations. Many Australian organizations adopt the Essential Eight to demonstrate due diligence and cyber resilience to customers, partners, insurers, and boards of directors. Cyber insurance providers in Australia increasingly require or incentivize Essential Eight implementation as conditions of coverage or for premium reductions.

Relationship to Other Frameworks and Standards

The Essential Eight Level 1 complements and aligns with various international cybersecurity frameworks and standards. Organizations already implementing ISO/IEC 27001 will find that Essential Eight controls map to several ISO 27001 Annex A controls, particularly in areas of access control (A.9), malware protection (A.12.2), and backup management (A.12.3). The Essential Eight provides more prescriptive technical guidance compared to ISO 27001's principle-based approach, making it valuable for organizations seeking specific implementation direction.

The Essential Eight also aligns well with the NIST Cybersecurity Framework, particularly the Protect function. Organizations can map Essential Eight strategies to NIST CSF subcategories to demonstrate how implementation supports broader cybersecurity objectives. Similarly, Essential Eight controls support compliance with the CIS Controls, particularly CIS Controls 2 (Inventory and Control of Software Assets), 3 (Data Protection), 4 (Secure Configuration), 5 (Account Management), and 7 (Continuous Vulnerability Management).

Organizations can also reference related maturity levels including Essential Eight Level 2 and Essential Eight Level 3 for progressive cybersecurity maturation. For organizations in specific sectors, frameworks like PCI DSS for payment card security, HIPAA for healthcare, and CMMC for defense contractors provide additional sector-specific requirements that complement Essential Eight implementations.

Common Challenges and Solutions

Organizations implementing Essential Eight Level 1 frequently encounter challenges that can delay or derail implementation. Understanding these common obstacles enables proactive planning and mitigation strategies.

Application Control Compatibility Issues: Application whitelisting can inadvertently block legitimate applications, particularly auto-updating software and applications that modify themselves during normal operation. Organizations should maintain comprehensive application inventories, test whitelisting rules thoroughly in non-production environments before production deployment, establish exception request processes for business-critical applications, and use hash-based or certificate-based rules rather than path-based rules where possible to reduce false positives.

Patch Management Disruptions: Rapid patching within two weeks can occasionally introduce compatibility issues or system instability that impact business operations. Organizations should implement robust testing procedures using representative test environments, stagger patch deployments to limit blast radius if issues occur, maintain rollback procedures for problematic patches, and consider vendor support timelines when scheduling patches for critical business systems with limited maintenance windows.

Legitimate Macro Dependencies: Some organizations rely heavily on macro-enabled documents for business processes, creating tensions with macro blocking requirements. Solutions include migrating macros to centralized trusted locations with proper access controls, digitally signing macros from known authors, exploring alternative automation approaches like PowerShell scripts or dedicated applications, and implementing compensating controls like enhanced email filtering for users requiring broader macro permissions based on business needs.

Administrative Privilege Resistance: Users accustomed to administrative rights often resist restrictions, claiming they need elevated privileges for daily work. Most objections reflect convenience preferences rather than genuine requirements. Organizations should clearly distinguish between user needs and wants, implement Just-In-Time (JIT) administrative access for occasional needs, provide self-service portals for common administrative tasks like printer installation, and secure executive sponsorship to enforce privilege restrictions consistently across all organizational levels including executives.

Frequently Asked Questions

What is the ACSC Essential Eight Maturity Level 1?

Essential Eight Maturity Level 1 is the baseline cybersecurity posture recommended by the Australian Cyber Security Centre. It requires organizations to implement partial controls across eight essential mitigation strategies designed to protect against common cyber threats including malware, ransomware, and phishing attacks. Level 1 focuses on implementing foundational security measures including application control on workstations, timely patching, macro security, application hardening, administrative privilege restrictions, multi-factor authentication for remote access, and daily backups with offline storage.

Is the Essential Eight mandatory for Australian organizations?

The Essential Eight is mandatory for Australian Government agencies under the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM) requirements. For private sector organizations, the framework remains voluntary but is strongly recommended as best practice guidance. Organizations in critical infrastructure sectors under the Security of Critical Infrastructure Act (SOCI Act) may face regulatory expectations to implement cybersecurity best practices including the Essential Eight. Many organizations adopt it voluntarily to demonstrate due diligence, meet cyber insurance requirements, and satisfy customer security expectations.

How long does it take to implement Essential Eight Level 1?

Implementation timeframes vary significantly based on organization size, existing security posture, and available resources. Small organizations with limited infrastructure may achieve Level 1 in 3-6 months with dedicated effort and appropriate resources. Medium-sized organizations typically require 6-9 months, while larger enterprises with complex environments typically require 9-12 months for full implementation across all locations and systems. A phased approach prioritizing high-impact strategies can deliver security benefits earlier in the implementation timeline while building toward comprehensive Level 1 coverage.

What is the difference between Level 1, Level 2, and Level 3?

Each maturity level represents increasing sophistication, coverage, and automation of security controls. Level 1 provides baseline protection with partially implemented controls focused on workstations and basic coverage. Level 2 adds stronger authentication, faster patching timelines (two weeks for operating systems), expanded coverage to servers including application control on servers, daily vulnerability scanning, and MFA for all users accessing important data. Level 3 represents advanced maturity with extremely aggressive patching (48 hours for critical vulnerabilities), phishing-resistant MFA, comprehensive application control across all systems, and enterprise-wide enforcement of all controls. Organizations typically progress through maturity levels over multiple years.

Can small businesses implement the Essential Eight?

Yes, the Essential Eight is designed to be accessible for organizations of all sizes including small businesses. Level 1 requirements are achievable without extensive cybersecurity budgets or dedicated security staff. Many Level 1 controls can be implemented using built-in Windows capabilities, cloud provider security features, and cost-effective third-party solutions. Small businesses should start with high-impact controls like administrative privilege restrictions, basic patching, and daily backups—which provide significant protection without substantial investment. Cloud-based security services often provide small businesses with enterprise-grade capabilities at affordable prices, making Level 1 implementation realistic even for resource-constrained organizations.