[
  {
    "slug": "essential-eight",
    "name": "Essential Eight",
    "title": "Essential Eight Assessment and Compliance",
    "description": "Essential Eight (Essential 8) assessment: we identify the controls and evidence that prove each strategy, and the gaps to your target maturity level.",
    "summary": "An Essential Eight assessment shows how well your business has put the Australian Signals Directorate's eight mitigation strategies in place. We help you identify the controls that meet each strategy and the evidence that can prove them, show you the gaps to the maturity level you need, and give you a prioritised plan in plain English.",
    "related": [
      {
        "label": "Free coverage check",
        "href": "https://check.teresec.com.au/?utm_source=teresec.com.au&utm_medium=framework&utm_campaign=essential-eight",
        "note": "See how far your existing licences take you towards each Essential Eight maturity level, in about three minutes."
      },
      {
        "label": "Sample coverage report",
        "href": "/sample-report.html#ISM-1504",
        "note": "Every ISM control with its Essential Eight maturity levels. This link opens at multi-factor authentication."
      },
      {
        "label": "Free Cyber Security Self-Check for Small Business",
        "href": "/blog/2026-09-08-free-security-self-check",
        "note": "Does Microsoft 365 Business Premium cover the Essential Eight, and which level should a small business aim for?"
      },
      {
        "label": "ISM September 2026: What Changed and What to Check",
        "href": "/blog/2026-09-17-ism-september-2026-update",
        "note": "This quarter's changes to the ISM, including the Essential Eight markings."
      }
    ],
    "sources": [
      {
        "label": "ASD, Essential Eight",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight",
        "note": "the baseline wording"
      },
      {
        "label": "ASD, Essential Eight maturity model (November 2023)",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model",
        "note": "the maturity levels, the same-level-across-all-eight advice, the minimum-set wording and independent assessment"
      },
      {
        "label": "ASD, Essential Eight maturity model FAQ",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model-faq",
        "note": "Maturity Level One for small to medium enterprises, and cyber insurance as Maturity Level Zero"
      },
      {
        "label": "ASD, Essential Eight assessment process guide (October 2024)",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-assessment-process-guide",
        "note": "assessing as a package, and evidence quality"
      },
      {
        "label": "ASD, Small business cyber security guide",
        "url": "https://www.cyber.gov.au/business-government/small-business-cyber-security/small-business-hub/small-business-cyber-security-guide",
        "note": "the Maturity Level One recommendation"
      },
      {
        "label": "Department of Home Affairs, Protective Security Policy Framework Release 2026",
        "url": "https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf",
        "note": "Requirements 0099 to 0106, Maturity Level Two"
      },
      {
        "label": "Queensland Government, Information and cyber security policy (IS18)",
        "url": "https://www.forgov.qld.gov.au/information-technology/queensland-government-enterprise-architecture-qgea/qgea-directions-and-guidance/qgea-policies-standards-and-guidelines/information-security-policy-is18",
        "note": "Requirement 3"
      },
      {
        "label": "ASD, Consultation on evolution of Essential Eight",
        "url": "https://www.cyber.gov.au/about-us/view-all-content/news/consultation-on-evolution-of-essential-eight",
        "note": "the Essentials series"
      }
    ],
    "attribution": "Quoted ASD material © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au."
  },
  {
    "slug": "ism",
    "name": "ISM",
    "title": "ASD ISM: Information Security Manual Assessment",
    "description": "The ASD Information Security Manual (ISM) explained: who must follow it, how it is built, what changed this quarter, and what an ISM assessment involves.",
    "summary": "The Information security manual (ISM) is the Australian Signals Directorate's cyber security framework: 49 principles and 1,143 controls, updated every quarter. We help you identify the ISM controls that apply to your systems, the controls and evidence you already have, and the gaps, in plain English.",
    "related": [
      {
        "label": "ISM September 2026: What Changed and What to Check",
        "href": "/blog/2026-09-17-ism-september-2026-update",
        "note": "The latest release in plain English: six things to check this quarter and every new control in ASD's words."
      },
      {
        "label": "Sample coverage report",
        "href": "/sample-report.html#ISM-2133",
        "note": "Every ISM control we count, by identifier, in ASD's wording. This link opens at the new AI agent identity control."
      },
      {
        "label": "Free coverage check",
        "href": "https://check.teresec.com.au/?utm_source=teresec.com.au&utm_medium=framework&utm_campaign=ism",
        "note": "See which ISM and Essential Eight controls your existing licences already reach, in about three minutes."
      },
      {
        "label": "Free Cyber Security Self-Check for Small Business",
        "href": "/blog/2026-09-08-free-security-self-check",
        "note": "How the coverage check reads your licences against the ISM and the Essential Eight."
      }
    ],
    "sources": [
      {
        "label": "ASD, Information security manual",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism",
        "note": "what the ISM is, who it is for, and the current release"
      },
      {
        "label": "ASD, Information security manual (September 2026), Using the cyber security framework",
        "url": "https://www.cyber.gov.au/sites/default/files/2026-08/Information%20security%20manual%20%28September%202026%29.pdf",
        "note": "the legal position, the principles' six functions, applicability markings, the risk management framework, assessors and authorising officers"
      },
      {
        "label": "ASD, ISM OSCAL release v2026.09.4",
        "url": "https://github.com/AustralianCyberSecurityCentre/ism-oscal/releases/tag/v2026.09.4",
        "note": "the counts of principles, chapters and controls, and the Essential Eight baselines"
      },
      {
        "label": "ASD, Archived ISM releases",
        "url": "https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/archived-ism-releases",
        "note": "the quarterly release cycle"
      },
      {
        "label": "Department of Home Affairs, Protective Security Policy Framework Release 2026",
        "url": "https://www.protectivesecurity.gov.au/system/files/2026-07/pspf-release-2026_6.pdf",
        "note": "Requirements 0084 and 0085"
      },
      {
        "label": "ASD, Infosec Registered Assessors Program (IRAP)",
        "url": "https://www.cyber.gov.au/irap",
        "note": "endorsed individual assessors"
      }
    ],
    "attribution": "Quoted ASD material © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au."
  }
]
