← Back to Library
ASD Top 35

ASD Top 35 (v1.0)

Full Name:
Australian Signals Directorate (ASD) Top 35
Acronym:
ASD Top 35
Type:
Cyber Hygiene Standard
Organization:
Australian Signals Directorate
Version:
1
Year Published:
2017
Popularity:
Low

Overview of ASD Top 35

The ASD Top 35 Mitigation Strategies represents the Australian Signals Directorate's original prioritized approach to cybersecurity, serving as the predecessor to the widely adopted ACSC Essential Eight framework. Published initially in 2011 and refined through 2017, the Top 35 identified and prioritized mitigation strategies based on ASD's extensive experience responding to cyber intrusions against Australian government and private sector organizations. The framework's evidence-based approach ranked strategies by their effectiveness at preventing successful cyber intrusions, with the top strategies capable of mitigating at least 85% of targeted cyber attacks.

The Top 35 framework emerged from ASD's analysis of actual cyber intrusions, identifying common attack patterns and determining which defensive measures would have prevented successful compromises. This practical, threat-informed approach differentiated the Top 35 from theoretical or checklist-based cybersecurity frameworks. Rather than attempting comprehensive coverage of all possible security controls, the Top 35 focused organizations' limited resources on the strategies providing maximum risk reduction. The framework's success led to its evolution into the more streamlined Essential Eight, which concentrated on the highest-priority strategies.

Evolution to the Essential Eight

The ASD Top 35 evolved into the Essential Eight around 2017 as ASD (later reorganized as ACSC) refined its guidance based on implementation feedback and emerging threats. The Essential Eight consolidated the top eight strategies from the Top 35, providing more detailed maturity levels and implementation guidance. Organizations that implemented the Top 35 found that the top eight strategies delivered disproportionate value compared to lower-ranked strategies, validating the focus on a smaller set of high-impact controls.

The transition from 35 to 8 strategies simplified implementation, reduced resource requirements, and improved organizational focus. However, the remaining 27 strategies from the original Top 35 remain valid cybersecurity practices that organizations should consider implementing based on their risk profiles and resources. The Essential Eight represents the minimum baseline, while the broader Top 35 provides additional depth for organizations seeking advanced maturity.

The Top 35 Strategies

The original Top 35 organized mitigation strategies into tiers based on effectiveness. The top tier strategies (which became the Essential Eight) received highest priority, with subsequent tiers providing additional defense depth.

Top Eight Strategies (Now the Essential Eight)

The highest-priority strategies from the Top 35 are: 1. Application whitelisting - Prevent execution of unapproved applications 2. Patch applications - Update security vulnerabilities in applications 3. Configure Microsoft Office macro settings - Block macros from the internet 4. User application hardening - Disable unnecessary application features 5. Restrict administrative privileges - Limit users with elevated access 6. Patch operating systems - Update OS security vulnerabilities 7. Multi-factor authentication - Require multiple authentication factors 8. Daily backups - Maintain recoverable copies of important data

For detailed information on implementing these strategies, see the Essential Eight Level 1, Level 2, and Level 3 framework pages.

Additional Tier Strategies

Beyond the top eight, the Top 35 included strategies addressing network segmentation, email security, web application security, system monitoring, incident response, and personnel security. These additional strategies provide defense-in-depth, particularly valuable for organizations facing sophisticated threats or protecting high-value assets. While not part of the Essential Eight baseline, organizations should evaluate these strategies based on their risk environment.

Key additional strategies include network segmentation and segregation, web application security testing, email content filtering, disabling unnecessary services and ports, implementing intrusion detection and prevention systems, conducting regular security assessments, implementing security incident management, and personnel security practices including background checks and security clearances for sensitive positions.

Framework Applicability and Adoption

While the Top 35 has been largely superseded by the Essential Eight for baseline cybersecurity, the framework remains relevant for organizations seeking comprehensive security programs beyond Essential Eight fundamentals. Government agencies, defense contractors, and critical infrastructure operators often implement controls beyond the Essential Eight, drawing from the broader Top 35 strategies.

Organizations currently using the Top 35 should transition to the Essential Eight as their baseline framework, then selectively implement additional Top 35 strategies based on risk assessments. The Essential Eight provides clearer maturity levels, more detailed implementation guidance, and better alignment with contemporary threats. However, the Top 35's comprehensive approach remains valuable for understanding the full spectrum of prioritized controls ASD identified.

Relationship to Other Frameworks and Standards

The Top 35 strategies align with international cybersecurity frameworks including NIST SP 800-53, ISO 27001, and CIS Controls. The prioritization approach influenced subsequent frameworks globally, with many adopting risk-based control prioritization rather than comprehensive checklists. Organizations implementing the Essential Eight satisfy the highest-priority Top 35 strategies, with additional controls addressing lower-priority strategies.

Organizations can reference related frameworks including ACSC Essential Eight for current baseline guidance, NIST Cybersecurity Framework for strategic risk management context, and PCI DSS for payment security requirements.

Frequently Asked Questions

Should organizations implement the Top 35 or Essential Eight?

Organizations should implement the Essential Eight as their baseline framework, as it provides clearer implementation guidance and maturity levels for the highest-priority strategies. The Essential Eight supersedes the Top 35 for baseline cybersecurity. However, organizations seeking advanced security maturity can reference the broader Top 35 for additional control ideas beyond the Essential Eight baseline.

What happened to strategies 9-35 from the Top 35?

While no longer promoted as a formal framework, strategies 9-35 remain valid cybersecurity practices. Many are covered by Essential Eight maturity progression (higher maturity levels include some Top 35 strategies beyond the basic eight). Others represent specialized controls that organizations implement based on specific risks or regulatory requirements. The Essential Eight focuses resources on highest-impact controls while the broader Top 35 provides additional depth for mature security programs.

How does the Top 35 relate to the Essential Eight Maturity Model?

The Essential Eight's three maturity levels (Levels 1, 2, and 3) provide progressive implementation depth for the top eight strategies, essentially incorporating elements of lower-priority Top 35 strategies into higher maturity levels. For example, Essential Eight Level 2 and Level 3 requirements include enhanced monitoring, vulnerability management, and incident response capabilities that were separate strategies in the original Top 35. The maturity model approach provides clearer implementation pathways than the numbered list format.

Is the Top 35 still relevant in 2024-2025?

While the Essential Eight framework is more current and recommended for new implementations, the Top 35's underlying principles remain relevant: prioritize security investments based on threat intelligence and effectiveness evidence, focus on preventing common attack techniques, and implement layered defenses. Organizations should not implement the Top 35 as a formal framework today but can reference it for understanding ASD's risk-based prioritization approach and identifying additional controls beyond Essential Eight fundamentals.

Where can I find the original Top 35 documentation?

The ACSC (formerly ASD) has archived the original Top 35 documentation, as it has been superseded by the Essential Eight. Historical references can be found in ACSC's "Strategies to Mitigate Cyber Security Incidents" publications from 2011-2017. Current guidance focuses on the Essential Eight framework with clear maturity levels. Organizations seeking comprehensive control coverage should implement Essential Eight at Level 2 or Level 3 rather than referencing the historical Top 35.