[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-163674-105":3,"detail-sidebar-cat-1-en-105":80,"doc-detail-163674-en":126},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":73,"head_meta":75,"extra_data":77,"updated_unix":79},105,"en","essential-eight-documentation-template-maturity-model-guidance","Essential Eight - Documentation Template - Maturity Model Guidance","","Essential Eight documentation template for implementing ASD’s Essential Eight Maturity Model as guided by the ASD Blueprint for Secure Cloud. Provides structured instructions aligned to maturity levels for key mitigation strategies, including patch applications and patch operating systems. Covers applicability across endpoints, on-premises and hybrid servers, plus explicit notes for systems that exclude online services. Users can adapt sections to match documentation needs and incorporate their own branding.",{"@graph":14,"@context":72},[15,34,55],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/template/","Template",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/template/presentations/","Presentations",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/template/essential-eight-documentation-template-maturity-model-guidance/163674/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/essential-eight-documentation-template-maturity-model-guidance/163674.png","ImageObject",442,249,{"name":42,"@type":43},"Kyle","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-29","2026-08-31",true,{"@type":52,"interactionType":53,"userInteractionCount":33},"InteractionCounter",{"@type":54},"ViewAction",{"@type":56,"mainEntity":57},"FAQPage",[58,64,68],{"name":59,"@type":60,"acceptedAnswer":61},"What is the purpose of the Essential Eight template?","Question",{"text":62,"@type":63},"The template supplies the content for ASD’s Essential Eight Maturity Model, following guidance from ASD’s Blueprint for Secure Cloud.","Answer",{"name":65,"@type":60,"acceptedAnswer":66},"How does the template describe patching for Windows endpoints?",{"text":67,"@type":63},"It specifies patch deployment using Microsoft Intune and application using Microsoft Defender for Endpoint, with different remediation timelines based on vendor criticality or active exploits.",{"name":69,"@type":60,"acceptedAnswer":70},"Does the template apply vulnerability scanning and patching to online services?",{"text":71,"@type":63},"No—when the system does not host or rely on online services within the organisation, the template states that scanning and patch application for those services are not applicable.","https://schema.org",{"og:url":32,"og:type":74,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":76,"canonical":32},"index,follow",{"doc_id":78,"site_id":7},163674,1790472156,{"code":4,"msg":81,"data":82},"success",[83,87,92,97,102,107,112,117,122],{"id":84,"doc_module":22,"doc_module_name":25,"category_name":29,"show_sort_weight":85,"slug":86},11,90,"presentations",{"id":88,"doc_module":22,"doc_module_name":25,"category_name":89,"show_sort_weight":90,"slug":91},12,"Resumes",80,"resumes",{"id":93,"doc_module":22,"doc_module_name":25,"category_name":94,"show_sort_weight":95,"slug":96},14,"Invoices",70,"invoices",{"id":98,"doc_module":22,"doc_module_name":25,"category_name":99,"show_sort_weight":100,"slug":101},15,"Posters",60,"posters",{"id":103,"doc_module":22,"doc_module_name":25,"category_name":104,"show_sort_weight":105,"slug":106},16,"Social Media",50,"social-media",{"id":108,"doc_module":22,"doc_module_name":25,"category_name":109,"show_sort_weight":110,"slug":111},17,"Forms",40,"forms",{"id":113,"doc_module":22,"doc_module_name":25,"category_name":114,"show_sort_weight":115,"slug":116},18,"Letters",30,"letters",{"id":118,"doc_module":22,"doc_module_name":25,"category_name":119,"show_sort_weight":120,"slug":121},21,"Paper Templates",5,"papers-templates",{"id":123,"doc_module":22,"doc_module_name":25,"category_name":124,"show_sort_weight":4,"slug":125},158,"General","general-158",{"code":4,"msg":81,"data":127},{"doc_id":78,"user_id":128,"nickname":42,"user_avatar":129,"doc_module":22,"category_id":84,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":33,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":135,"language":136,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":12,"update_tm":140,"read_time":141},3985741905716,"https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d","Essential Eight Documentation | Template\nThis template provides the content of ASD’s Essential Eight Maturity Model as advised on ASD’s Blueprint for Secure Cloud. Users can use their own branding. users should remove or add sections relevant to their documentation requirement. Delete this and all other pre-populated instructions from the final version of your report.\n\u0003Table of Contents\n\u0013TOC \\o \"1-1\" \\h \\z \\u\u0014\u0015\u0004\n\u000f\nEssential Eight\n\u003CSYSTEM-NAME> targets the following maturity levels against each Essential Eight Mitigation Strategy:\n\u000f\nPatch applications\nApplicability\nThe Patch Applications mitigation strategy is applicable to the appropriate patching of applications for the following components of \u003CSYSTEM-NAME>:\nEndpoints (Windows laptops and desktops)\n\u003CON-PREMISES SERVERS>\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nMaturity Level\nImplementation\nAsset discovery\n\u003CASSET-DISCOVERY-TOOL> is used to scan for all assets within \u003CSYSTEM-NAME>.\n\u003CASSET-DISCOVERY-TOOL> performs an asset discovery scan on a \u003CFORTNIGHTLY> basis.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nVulnerability scanning\n\u003CVULNERABILITY-SCANNING-TOOL> is used to scan for all application vulnerabilities on endpoints and servers within \u003CSYSTEM-NAME>. \u003CVULNERABILITY-SCANNING-TOOL> is configured to update its vulnerability database on a \u003Cnightly> basis.\nWindows endpoints\n\u003CVULNERABILITY-SCANNING-TOOL> is configured to scan all Windows endpoints discovered by \u003CASSET-DISCOVERY-TOOL>, performing vulnerability scans on a weekly basis.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nHybrid servers\n\u003CVULNERABILITY-SCANNING-TOOL> is configured to scan all hybrid servers discovered by \u003CASSET-DISCOVERY-TOOL>, performing vulnerability scans on a daily basis.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nServers for online services\n\u003CSYSTEM-NAME> does not include the hosting of online services, nor does it leverage the use of online services within \u003CORGANISATION-NAME> as part of its operation, and as such the scanning of vulnerabilities in these services is not applicable.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nPatching\nWindows endpoints\nPatches for all applications on windows endpoints are managed and deployed using Microsoft Intune, and applied using Microsoft Defender for Endpoint.\nIn accordance with the \u0013 HYPERLINK \"https://blueprint.asd.gov.au/security-and-governance/general-documentation\" \\h \u0014\u003CSYSTEM-NAME> Vulnerability and Patch Management Process\u0015, vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products discovered by \u003CVULNERABILITY-SCANNING-TOOL> are applied within 48 hours where these vulnerabilities are assessed as critical by vendors or when working exploits exist, and applied within 2 weeks otherwise.\nPatches for vulnerabilities in all other applications on \u003CSYSTEM-NAME> endpoints are applied within 1 month.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nHybrid servers\nPatches for all applications on hybrid servers are applied using \u003Cserver patch deployment mechanism>.\nIn accordance with the \u0013 HYPERLINK \"https://blueprint.asd.gov.au/security-and-governance/general-documentation\" \\h \u0014\u003CSYSTEM-NAME> Vulnerability and Patch Management Process\u0015, vulnerabilities in web browsers and security products discovered by \u003CVULNERABILITY-SCANNING-TOOL> are applied within 48 hours where these vulnerabilities are assessed as critical by vendors or when working exploits exist, and applied within 2 weeks otherwise.\n\u003CSYSTEM-NAME> hybrid servers do not have office productivity suites, web browser extensions, email clients, PDF software (other than web browsers), or Adobe Flash Player installed.\nPatches for vulnerabilities in all other applications on \u003CSYSTEM-NAME> hybrid servers are applied within 1 month.\n\u003CINSERT ADDITIONAL INFORMATION AS APPROPRIATE>\nServers for online services\n\u003CSYSTEM-NAME> does not include the hosting of online services, nor does it leverage the use of online service","cbCaigay5hvMS3oK","https://ap.wps.com/l/cbCaigay5hvMS3oK","docx",64183,56,"English","# Essential Eight\n## Patch applications\n### Applicability\n### Maturity level and implementation\n### Asset discovery\n### Vulnerability scanning\n### Patching\n### Removal of unsupported applications\n## Patch operating systems\n### Applicability\n### Maturity level and implementation\n### Asset discovery\n### Vulnerability scanning","[{\"question\":\"What is the purpose of the Essential Eight template?\",\"answer\":\"The template supplies the content for ASD’s Essential Eight Maturity Model, following guidance from ASD’s Blueprint for Secure Cloud.\"},{\"question\":\"How does the template describe patching for Windows endpoints?\",\"answer\":\"It specifies patch deployment using Microsoft Intune and application using Microsoft Defender for Endpoint, with different remediation timelines based on vendor criticality or active exploits.\"},{\"question\":\"Does the template apply vulnerability scanning and patching to online services?\",\"answer\":\"No—when the system does not host or rely on online services within the organisation, the template states that scanning and patch application for those services are not applicable.\"}]","Essential Eight - Documentation Template - Maturity Model Guidance | DOCX",1788146164,20]