Compliance — ACSC Essential Eight
Essential Eight Maturity Level 2-3 evidence — all eight strategies
The Australian Cyber Security Centre's Essential Eight Maturity Model is the baseline security standard for Australian Government agencies. ManySignal monitors all eight strategies and provides ML2-ML3 evidence for IRAP assessments — including pre-ransomware detection, MFA monitoring, and privileged access control evidence.
Essential Eight strategy mapping — ManySignal coverage
| Mitigation Strategy | Maturity Level | ManySignal Monitoring Evidence |
|---|---|---|
| Patch Applications | ML2-3 | Exploitation attempt detection for unpatched vulnerabilities — successful exploit indicators trigger immediate alerts |
| Patch Operating Systems | ML2-3 | Lateral movement via OS-level exploits detected via network behaviour and process anomalies |
| Multi-Factor Authentication | ML2-3 | MFA bypass, MFA fatigue attack, and token replay detection across identity providers |
| Restrict Administrative Privileges | ML1-3 | Privileged account anomaly detection — admin account usage outside approved scope, privilege escalation, service account misuse |
| Application Control | ML2-3 | Unauthorised application execution detection via endpoint telemetry and process name/hash baselining |
| Restrict Microsoft Office Macros | ML2-3 | Macro execution in Office documents detected via endpoint telemetry — suspicious macro-spawned process chains flagged |
| User Application Hardening | ML1-3 | Browser-based attack indicators, Java/Flash execution (where applicable), and insecure application configuration anomalies |
| Regular Backups | ML2-3 | Pre-ransomware indicators — shadow copy deletion (vssadmin), backup service termination, bulk file encryption detected before completion |
Certification and assessment status
ManySignal's Australia deployment (AWS Sydney) aligns to the ASD Cloud Security Guidance. IRAP assessment is in progress. Assessment documentation including the Cloud Security Assessment report is available to Australian Government customers under NDA. Contact au-sales@manysignal.com for government deployment documentation.
Essential Eight — common questions
What are the Essential Eight Maturity Levels, and which does ManySignal support?
The ACSC Essential Eight Maturity Model has four levels: ML0 (no controls), ML1 (partial controls), ML2 (controls applied across the environment), and ML3 (controls with additional resilience measures). ManySignal provides monitoring evidence for ML2 and ML3 assessments — demonstrating that controls are applied consistently and anomalies in their application are detected and responded to.
Does ManySignal help with Essential Eight assessments by IRAP assessors?
ManySignal provides the monitoring evidence that IRAP (Information Security Registered Assessors Program) assessors review when assessing Essential Eight maturity. Specifically: privileged access anomaly detection evidence (Restrict Administrative Privileges), MFA monitoring evidence (Multi-Factor Authentication strategy), and pre-ransomware indicator detection evidence (Patch Applications and Regular Backups strategies).
How does ManySignal detect ransomware as part of the Regular Backups strategy monitoring?
The Essential Eight's Regular Backups strategy includes ensuring backups can be restored and that backup systems themselves are protected. ManySignal monitors for pre-ransomware indicators that threaten backup systems: volume shadow copy deletion commands (vssadmin delete shadows), backup agent service termination, and access to backup server admin consoles from unusual hosts — all of which precede ransomware encryption payload deployment.
Which Australian Government agencies require Essential Eight compliance?
All Australian Government non-corporate Commonwealth entities (NCCEs) must implement the Essential Eight as mandated by the Australian Government Information Security Manual (ISM) and PSPF (Protective Security Policy Framework). Corporate Commonwealth entities and GBEs are expected to comply. State government agencies increasingly adopt Essential Eight as their baseline security framework as well.
Does ManySignal integrate with Microsoft Defender and Intune for Essential Eight monitoring?
Yes. ManySignal ingests Microsoft Defender for Endpoint telemetry (for application control, exploit detection, and process anomalies), Microsoft Entra ID (for MFA monitoring and privileged access events), and Microsoft Intune (for device compliance state). Combined with network flow data, this covers the monitoring evidence requirements for all eight strategies at ML2 maturity.
Deploy Essential Eight monitoring in Australia
Connect your Microsoft 365, Defender for Endpoint, and network telemetry. We'll show you ML2 evidence generation for all eight strategies in your first session.