Module 5: The Australian cyber context
Estimated time: 3-4 hours (including the lab) · Prerequisites: M0-M4
This is the module that makes you an Australian cyber candidate rather than a generic one. Global courses teach NIST and ISO; Australian employers interview you on the Essential Eight, the ISM, the Privacy Act and who does what at the ACSC. Career changers who know this material cold (especially GRC applicants) stand out immediately.
Security+ SY0-701 mapping: primarily Domain 5 (Security Program Management & Oversight), with governance and compliance concepts that also reinforce Domain 1.
What you'll get from this module
- Explain who's who in Australian cyber security: ASD, the ACSC, and cyber.gov.au.
- List and explain all eight Essential Eight mitigation strategies and the Maturity Model.
- Describe the ISM and its six functions.
- Explain the Privacy Act 1988, the APPs, and the Notifiable Data Breaches scheme at a working level.
- Summarise the 2023-2030 Australian Cyber Security Strategy in one minute.
- Produce an Essential Eight self-assessment: a genuine portfolio artefact for GRC applications.
1. Who's who: ASD, ACSC and cyber.gov.au
- The Australian Signals Directorate (ASD) is the Commonwealth agency responsible for signals intelligence and cyber security. It both defends Australian networks and (separately) conducts offensive cyber operations for the government.
- The Australian Cyber Security Centre (ACSC) sits within ASD and is the public-facing arm: it publishes national guidance, issues alerts and advisories, and helps organisations and individuals respond to incidents.
- cyber.gov.au is the ACSC's website: the single national source of cyber security guidance. When an Australian employer asks "where would you check official guidance?", this is the answer.
- 1300 CYBER1 (1300 292 371) is the Australian Cyber Security Hotline: 24/7 help for individuals and organisations dealing with an incident.
- ReportCyber (via cyber.gov.au) is the national online portal for reporting cybercrime. Reports are triaged and routed to the right police jurisdiction.
Interview tip: being able to say "I'd report it through ReportCyber and check the ACSC's current advisories" signals local knowledge that imported courses don't teach.
2. The Essential Eight: the framework employers actually name
ASD publishes a longer list of Strategies to Mitigate Cyber Security Incidents; the Essential Eight are the eight it considers the most effective baseline for internet-connected IT networks. Job ads and interviews reference it constantly because Commonwealth entities are expected to implement it and much of the private sector has adopted it as a de facto benchmark.
The eight strategies:
| # | Strategy | What it prevents (in one line) |
|---|---|---|
| 1 | Patch applications | Attackers exploiting known flaws in apps like browsers and Office |
| 2 | Patch operating systems | Exploitation of known OS vulnerabilities |
| 3 | Multi-factor authentication | Stolen passwords being enough to get in |
| 4 | Restrict administrative privileges | One compromised account owning the whole environment |
| 5 | Application control | Unapproved/malicious programs executing at all |
| 6 | Restrict Microsoft Office macros | A classic malware delivery channel via documents |
| 7 | User application hardening | Risky features (e.g. legacy web tech) being abused |
| 8 | Regular backups | Ransomware or disaster becoming unrecoverable |
Notice the logic: the first four stop attackers getting in and escalating; the next three shrink the attack surface; backups make the worst case survivable.
The Maturity Model
Implementation is measured against four maturity levels:
| Level | Meaning | Typical fit |
|---|---|---|
| ML0 | Weaknesses in overall posture: the strategy isn't meaningfully implemented | Starting point |
| ML1 | Protects against commodity attackers using widely available tradecraft | Roughly right for SMEs |
| ML2 | Protects against more capable attackers willing to invest in a target | Roughly right for larger enterprises |
| ML3 | Protects against adaptive, highly capable adversaries | Critical infrastructure / high-threat environments |
The intent is to implement a maturity level across all eight strategies before moving up, rather than maxing out one strategy and ignoring the rest.
Note on the "typical fit" column: ASD's own guidance does suggest these levels "may be suitable for" SMEs (ML1), large enterprises (ML2), and critical-infrastructure / high-threat organisations (ML3). But the levels are fundamentally defined by the adversary tradecraft they defend against, so the right target for any organisation is driven by its risk and threat environment, not simply its headcount.
Why GRC candidates must know this cold: Essential Eight assessments, uplift projects and gap analyses are bread-and-butter junior GRC work in Australia. Being able to name all eight unprompted, explain the maturity levels, and talk through a gap assessment is a realistic interview differentiator.
In June 2026 ASD announced the Essential Eight will be phased out and replaced by a new "Essentials" series (starting with Essentials for enterprise IT), on roughly a two-year timeline, with a public consultation running to 12 July 2026. The Essential Eight remains current guidance today and is still very much interview-relevant, so it's worth knowing cold, but expect change, and always check the Essential Eight page on cyber.gov.au (and any successor "Essentials" guidance) for the current version rather than relying on a course, a blog, or this page.
3. The ISM: Australia's control catalogue
The Information Security Manual (ISM) is ASD's cyber security framework for protecting systems and data: a set of principles and detailed controls, used heavily by government and by suppliers to government. Where the Essential Eight is a prioritised baseline, the ISM is the full catalogue.
It is organised around six functions:
- Govern: roles, policies, risk management
- Identify: knowing your assets and their value
- Protect: implementing controls
- Detect: spotting incidents
- Respond: handling incidents
- Recover: restoring operations
The ISM is updated periodically (historically around quarterly), so practitioners cite it by release date. You don't memorise the controls: you know what it is, how it's structured, and where to find it (cyber.gov.au).
4. Privacy law: the Privacy Act, the APPs and the NDB scheme
Cyber and privacy are inseparable in Australian GRC work.
- The Privacy Act 1988 (Cth) is the core federal privacy law. It applies to Australian Government agencies and most private organisations with annual turnover over $3 million (plus some smaller ones, such as health providers).
- It contains the 13 Australian Privacy Principles (APPs): obligations covering the collection, use, disclosure, quality, security (APP 11) and correction of personal information. You don't need to recite all 13; you do need to know they exist, that APP 11 requires reasonable steps to secure personal information, and where to look them up.
- The Notifiable Data Breaches (NDB) scheme requires covered organisations to notify affected individuals and the regulator when an eligible data breach occurs: meaning unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to individuals, and that harm can't be prevented with remedial action.
- The regulator is the Office of the Australian Information Commissioner (OAIC). It receives breach notifications, publishes statistics, investigates, and can seek significant penalties.
Why it matters for entry roles: in a SOC, "does this incident involve personal information?" changes the escalation path. In GRC, NDB assessment procedures and privacy impact work are everyday tasks.
5. The national strategy in one minute
The 2023-2030 Australian Cyber Security Strategy (Department of Home Affairs) sets the goal of making Australia a world leader in cyber security by 2030, delivered across three horizons:
- Horizon 1 (2023-2025), strengthen foundations: address gaps, build better protections for citizens and businesses.
- Horizon 2 (2026-2028): scale cyber maturity across the whole economy, including the workforce growth this course is aimed at.
- Horizon 3 (2029-2030): lead globally in cyber capability and norms.
One paragraph is genuinely all you need, but knowing the strategy exists, who owns it (Home Affairs) and its 2030 ambition shows you follow the national picture.
6. Critical infrastructure and recent history
SOCI in one paragraph: the Security of Critical Infrastructure Act 2018 (SOCI Act) imposes security and incident-reporting obligations on operators of critical infrastructure: energy, water, healthcare, communications, financial services and more. If you end up working for (or consulting to) one of these operators, SOCI obligations will shape your job. For now, know it exists.
Why Australia takes this seriously, two dates every candidate should know:
- Optus (2022): a breach exposed personal details of millions of Australian customers, triggering national debate on data retention and breach penalties.
- Medibank (2022): attackers stole sensitive health claims data and published it when the ransom was refused, affecting millions of Australians.
These two incidents reshaped Australian law, regulator attitudes and hiring budgets. They're part of why the roles you're training for exist.
🧪 Lab 5: Essential Eight self-assessment (portfolio artefact)
This lab produces a one-page gap assessment: exactly the kind of document junior GRC analysts write, and a strong portfolio piece.
Pick a subject: a small organisation you know well (a past employer, a family business, a sporting club) or your own household IT. No permission is needed because you're assessing from your own knowledge. You are not scanning or probing anything.
Steps:
- Open the current Essential Eight page and skim the Maturity Level 1 requirements for each strategy.
- Create a table with four columns: Strategy · Current state · ML1 met? (Yes/Partial/No) · Gap and recommended action.
- Work through all eight strategies honestly. Examples: Are OS updates applied automatically and promptly? Is MFA on for email and important accounts? Who has admin rights, and do they use those accounts for daily browsing? Are there backups, and have they ever been test-restored?
- Write a three-sentence executive summary at the top: overall posture, the two most important gaps, and your top recommendation.
- Keep it to one page. Save it (PDF or Markdown in your portfolio repo) with any identifying details of a real organisation removed or anonymised.
Lab success = a one-page assessment covering all eight strategies with an honest ML1 verdict and at least one concrete recommendation per gap.
In a GRC interview, "I've done an Essential Eight ML1 gap assessment. Here's how I structured it" is a genuinely strong answer to "what experience do you have with frameworks?"
Self-check
Answer before you reveal: the attempt is what makes it stick. Your score and card ratings are saved on this device only.
Check your understanding
Commit to an answer before you check: the attempt is what makes it stick. Your first answer to each question is the one scored; practising again afterwards doesn't change it. Saved on this device only.
These are the names, numbers and acronyms Australian interviewers actually probe (ASD or ACSC, ML1 or ML3, OAIC or ReportCyber) so drill them until the right one surfaces without thinking.
Drill the key terms
Say your answer out loud (or in your head) before revealing. Recall is the workout. "Knew it" pushes a card's next review further out; "Review again" brings it back today.
Card 1 of 18
ASD vs ACSC: who does what?
Portions of this module summarise and adapt material from cyber.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. Changes were made: content was summarised and restructured for this course.
Next module
➡️ M6: Identity & access management, the modern security perimeter: authentication, MFA, directories and the identity lifecycle.