Australian Essential Eight and the AIC Kits
The Essential Eight are eight mitigation strategies published by the Australian Cyber Security Centre. Analog Informatics Corporation (AIC) kits cover administrative privilege, application control, and multi-factor authentication on the systems they manage. Patching and backups stay with the organization. This page is not a maturity assessment.

The Eight Strategies
| Strategy | What the Kit Does |
|---|---|
| Patch applications | Current State Compliance can record a missing patch. Patching stays with the organization. |
| Patch operating systems | The organization patches. The kit can record the finding. |
| Multi-factor authentication | Kit sign-in with another step beyond a password. |
| Restrict administrative privileges | Privileged User Management removes standing administrator rights and grants time-bound elevation. |
| Application control | Privileged User Management application control on enrolled Windows systems. Apple Mac and Unix/Linux coverage is expanding. |
| Restrict Microsoft Office macros | Office macro policy stays with the organization. |
| User application hardening | Configuration compliance checks an approved baseline on enrolled systems. |
| Regular backups | Backups stay with the organization. The Assessment Binder can store the record. |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.