ACSC L3 (v2022)
Overview of ACSC Essential Eight Level 3
Essential Eight Maturity Level 3 represents the highest tier of the ACSC's cybersecurity maturity model, providing defense-in-depth protection against sophisticated adversaries including nation-state actors and advanced persistent threat (APT) groups. Released as part of the 2022 Maturity Model update, Level 3 achieves comprehensive security through aggressive patching timelines (48 hours for critical vulnerabilities), phishing-resistant multi-factor authentication, comprehensive application control across all systems, continuous monitoring, automated security operations, and rigorous operational discipline. Level 3 is designed for organizations protecting national security information, critical infrastructure, high-value intellectual property, and systems targeted by advanced adversaries.
Organizations implementing Level 3 demonstrate elite cybersecurity maturity suitable for defending against the most sophisticated threat actors who invest significant resources in targeted intrusions, develop or acquire zero-day exploits, and conduct multi-stage campaigns over extended timeframes. The 2022 refinements emphasize automation, continuous validation, resilience against supply chain compromises, and security operations center (SOC) capabilities. While Level 1 and Level 2 address the majority of cybercrime threats, Level 3 specifically targets sophisticated actors employing custom malware, advanced tradecraft, and patient, persistent reconnaissance and intrusion operations.
Level 3 Enhanced Requirements
Level 3 builds upon Level 2 foundations with requirements that push organizations toward advanced security operations capabilities, comprehensive automation, and continuous improvement. These enhanced requirements demand significant investment in technology, highly skilled personnel, mature operational processes, and organizational commitment to security excellence.
Extreme Patching Timelines
Level 3 mandates patching critical vulnerabilities within 48 hours of release for both applications and operating systems, with other security vulnerabilities patched within two weeks. This aggressive "patch or perish" approach minimizes the window during which sophisticated actors can weaponize newly disclosed vulnerabilities. Organizations must implement fully automated patch testing and deployment infrastructure, maintain 24/7 patch management capabilities, and develop processes for emergency patching outside normal change windows. The 48-hour requirement covers critical vulnerabilities in internet-facing services and critical systems, which advanced actors prioritize for initial access and privilege escalation.
Phishing-Resistant Multi-Factor Authentication
Unlike Level 1 and Level 2 which accept any MFA method including SMS and push notifications, Level 3 requires phishing-resistant MFA for all users accessing any system. Acceptable methods include hardware security keys (FIDO2/WebAuthn), certificate-based authentication, Windows Hello for Business, and smart cards. These methods resist sophisticated phishing attacks, adversary-in-the-middle attacks, MFA push notification fatigue attacks, and SIM-swapping attacks that defeat SMS and standard push-notification MFA. Organizations must deploy phishing-resistant MFA infrastructure enterprise-wide and ensure compatibility with all critical business applications including legacy systems.
Comprehensive Application Control
Level 3 extends application control to all workstations and servers throughout the enterprise without exception, including internal systems not exposed to the internet. Organizations must implement driver and kernel-level protection to prevent rootkit installation, maintain centralized management of application control policies across all systems, block unsigned or incorrectly signed software, and validate software integrity through publisher certificates or cryptographic file hashes. This comprehensive approach prevents advanced malware including those with kernel-level rootkit components, nation-state malware with code-signing capabilities, and sophisticated threats designed to evade detection.
Enhanced Macro Security and Application Hardening
Beyond blocking macros from the internet, Level 3 requires disabling macros entirely for users who don't require them for business purposes. Organizations must identify legitimate business uses through thorough business process analysis, restrict macro-enabled documents to trusted locations with centralized management and monitoring, and implement code signing for approved macros with regular review of signing certificates. Application hardening extends to disabling unnecessary protocols, services, and features across all applications without exception. Web browsers must block Flash, Java, all browser extensions except those specifically approved through formal processes, advertisements, and unnecessary plugins. Email systems must remove active content and disable automatic preview of attachments that could trigger exploits.
Advanced Privileged Access Management
Level 3 introduces sophisticated privileged access management (PAM) requirements including just-in-time (JIT) administrative access that grants privileges only when needed, session recording of all privileged activities, credential vaulting in encrypted storage, and workflow-based approval processes for elevated access. Privileged credentials must be unique per account, rotated regularly through automation (at minimum monthly or after each use), and protected in encrypted vaults that log all access. Organizations must implement separate administrative workstations or jump servers for privileged activities, preventing compromise of standard user systems from leading to administrative access. Session recording enables forensic analysis of privileged activities and deters insider threats through accountability mechanisms.
Continuous Vulnerability Assessment
Level 3 requires continuous vulnerability assessment rather than daily scanning, with authenticated scanning that assesses vulnerabilities inside systems, not just network-level vulnerabilities detectable externally. Vulnerability management processes must automatically prioritize remediation based on multiple factors including exploitability (CVSS scores, exploit availability, exploit complexity), threat intelligence about active exploitation in the wild, and asset criticality to business operations. Integration with security information and event management (SIEM) and threat intelligence platforms enables correlation between vulnerabilities and actual threat activity. Organizations should achieve mean time to remediate (MTTR) metrics of 48 hours for critical vulnerabilities and two weeks for high-severity findings across the entire environment.
Immutable and Tested Backups
Level 3 mandates immutable backup storage that cannot be encrypted, deleted, or modified by ransomware or malicious insiders, even with administrative credentials. Organizations must implement air-gapped backup copies physically disconnected from networks or write-once-read-many (WORM) storage technology. Restoration testing must occur quarterly for all critical systems with documented recovery procedures, measured recovery time objectives (RTOs) and recovery point objectives (RPOs), and trained personnel capable of executing recovery operations. Organizations should maintain offline backup copies stored in geographically separate locations and test failover to backup sites as part of business continuity exercises. Backup integrity validation through checksums and encryption verification prevents adversaries from corrupting backups during long-term persistent access preceding ransomware deployment.
Framework Applicability and Adoption
Essential Eight Level 3 is recommended for Australian government agencies handling national security information classified at PROTECTED or above, critical infrastructure operators in sectors like energy, telecommunications, water, and healthcare, defense contractors and supply chain partners, organizations experiencing confirmed advanced persistent threat activity, and enterprises protecting intellectual property of strategic importance or national security relevance. The ACSC considers Level 3 appropriate for defending against adversaries with sophisticated capabilities including custom malware development, zero-day exploit acquisition and deployment, long-term persistence operations, and nation-state-level resources.
Private sector organizations should implement Level 3 when facing confirmed advanced threat activity, when protecting information with national security implications, when operating critical infrastructure that could impact public safety if compromised, or when required by regulatory obligations or contractual commitments. Level 3 represents a substantial commitment requiring dedicated executive sponsorship, significant cybersecurity budgets (typically 7-10% of IT spending), and mature security operations capabilities including 24/7 security operations centers. Organizations should not attempt Level 3 without first achieving and sustaining Level 2 maturity across all eight strategies.
Implementation Strategies and Best Practices
Advancing to Level 3 requires transforming cybersecurity from a support function to a core operational capability integrated into all business processes. Organizations need security operations centers with 24/7 monitoring and response capabilities, threat intelligence programs providing actionable insights, automation platforms integrating security tools into cohesive defense ecosystems, and highly skilled security personnel capable of detecting and responding to sophisticated adversary tactics.
Build Security Operations Capabilities: Level 3's 48-hour patching, continuous monitoring, and advanced threat detection requirements necessitate 24/7 security operations. Organizations should establish security operations centers (SOCs) with defined procedures for vulnerability management, emergency patch deployment, incident response, threat hunting, and forensic investigation. Consider managed security service providers (MSSPs) or managed detection and response (MDR) providers for after-hours coverage if internal 24/7 staffing is not feasible. SOC personnel need specialized training in advanced threat tactics, techniques, and procedures (TTPs) including nation-state threat actor methodologies, to recognize sophisticated adversary activity often designed to blend with normal operations.
Automate Relentlessly: Human-driven processes cannot consistently meet Level 3 timelines and coverage requirements without introducing unacceptable risk of error or delay. Implement security orchestration, automation, and response (SOAR) platforms that automate routine tasks including vulnerability assessment, patch testing and deployment, incident triage and initial response, and compliance reporting. Use infrastructure-as-code and configuration management tools (Ansible, Terraform, Chef, Puppet) to enforce security configurations automatically across all systems. Automation not only enables Level 3 compliance but also frees skilled security personnel to focus on high-value activities like threat hunting, security architecture, and adversary emulation exercises.
Integrate Threat Intelligence: Level 3 organizations should consume multiple threat intelligence feeds about vulnerabilities under active exploitation, adversary tactics targeting their sector or geopolitical region, and indicators of compromise (IOCs) from recent intrusions. Integrate threat intelligence with vulnerability management to prioritize patches for vulnerabilities being actively exploited, security monitoring systems to detect known adversary TTPs, and incident response processes to accelerate investigation and containment. Participate in information sharing communities including sector-specific Information Sharing and Analysis Centers (ISACs), government-sponsored sharing programs, and trusted peer networks to receive early warnings about emerging threats and adversary campaigns.
Implement Zero Trust Architecture: Level 3's comprehensive control coverage, phishing-resistant MFA, and continuous validation requirements align naturally with zero trust security principles. Adopt identity-centric security that verifies every access request regardless of network location or device, micro-segmentation that limits lateral movement through granular network controls, and continuous trust evaluation that adjusts access based on behavior analytics and risk signals. Zero trust architecture simplifies Level 3 implementation by establishing consistent security controls across on-premises, cloud, and hybrid environments while reducing reliance on perimeter defenses that sophisticated adversaries routinely bypass.
Relationship to Other Frameworks and Standards
Essential Eight Level 3 achieves security outcomes comparable to international standards for protecting classified information and critical infrastructure. The framework aligns with NIST SP 800-53 at the HIGH baseline suitable for federal information systems processing classified information or critical to national security. Organizations implementing Level 3 satisfy most technical requirements of ISO 27001 with advanced implementations of key controls exceeding typical ISO certification requirements.
The NIST Cybersecurity Framework Implementation Tier 3 (Repeatable) and Tier 4 (Adaptive) correspond to Level 3's maturity expectations around risk-informed decision making, integrated risk management across the enterprise, and continuous improvement based on lessons learned. CIS Controls Implementation Group 3 (IG3) requires similar comprehensive control coverage for organizations defending against sophisticated adversaries including nation-state actors.
Organizations can reference related frameworks including Essential Eight Level 1 and Essential Eight Level 2 as progressive maturity stages, NIST SP 800-171 for controlled unclassified information protection, and CMMC Level 3 for defense contractor advanced requirements.
Frequently Asked Questions
What organizations need Essential Eight Level 3?
Level 3 is designed for organizations protecting national security information, critical infrastructure that could impact public safety, defense contractors handling classified information, and enterprises experiencing confirmed advanced persistent threat activity or targeted by nation-state actors. If your organization handles PROTECTED or SECRET classified information, operates critical infrastructure in energy/telecommunications/water/healthcare sectors, or has experienced confirmed nation-state intrusion activity, Level 3 is appropriate. Most commercial organizations not facing advanced threats should target Level 2 instead—Level 3 requires substantial investment justified only by high-consequence threat scenarios where sophisticated adversaries actively target the organization.
How long does it take to achieve Level 3 from Level 2?
Organizations with mature Level 2 implementations typically require 12-24 months to achieve comprehensive Level 3 maturity. Phishing-resistant MFA deployment across all systems including legacy applications, building 24/7 security operations capabilities with trained personnel, and achieving consistent 48-hour patching for critical vulnerabilities represent the longest-duration activities. Organizations should plan multi-year roadmaps with phased implementation prioritizing highest-value systems and most critical requirements rather than attempting immediate Level 3 achievement across all systems simultaneously. Progressive advancement ensures sustainable operations, builds necessary expertise through experience, and allows organizational culture to adapt to heightened security requirements.
Can small organizations achieve Level 3?
Level 3 presents significant challenges for small organizations with limited cybersecurity resources, budget constraints, and lack of specialized security personnel. However, small organizations protecting high-value information or facing advanced threats may need Level 3 security outcomes despite resource constraints. Solutions include managed security service providers (MSSPs) for SOC capabilities and 24/7 monitoring, cloud-native security tools that provide advanced capabilities without infrastructure investment, security automation that compensates for limited staff, and carefully scoped Level 3 implementation focused on highest-value systems rather than attempting enterprise-wide coverage. Small organizations should rigorously scope Level 3 implementation to systems processing the most sensitive information rather than attempting to achieve Level 3 across all organizational systems.
How does Level 3 defend against zero-day exploits?
Level 3 doesn't prevent zero-day exploitation (by definition, no patch exists initially), but it significantly limits impact through defense-in-depth. Application control prevents unknown malware from executing even after successful exploitation, phishing-resistant MFA blocks initial access attempts via credential compromise, administrative privilege restrictions limit what attackers can accomplish after initial compromise, comprehensive monitoring detects anomalous behavior indicating exploitation attempts, network segmentation contains compromised systems and limits lateral movement, and immutable backups enable recovery if attackers achieve their objectives. Advanced adversaries with zero-days can still penetrate Level 3 environments through persistent effort, but they face substantially greater difficulty establishing persistence, moving laterally to high-value targets, and achieving mission objectives before detection. Level 3's value against zero-days lies primarily in detection speed, containment effectiveness, and recovery capability rather than prevention.