Skip to main content
Westlink Intranet

Command Palette

Search for a command to run...

?
OFFICIAL
Back to Compliance

Essential Eight Maturity Model — Maturity Level Two

Essential Eight Maturity Level 2 — ASD Mitigation Strategies for Westlink Logistics

Requirements
107
Last reviewed
15/04/2026
Next review
15/04/2027
Source
ASD Essential Eight Maturity Model, November 2023

Reconciliation notes

E8 ML2 compliance library is a curated build because the source is a PDF-converted markdown (ASD Essential Eight Maturity Model, November 2023), not an EPUB with numbered clauses. All 8 mitigation strategies are captured at ML2 only — ML1 and ML3 are out of scope for this file. Shared logging / cybersecurity-event-analysis / incident-reporting / IR-plan controls are captured per-strategy as the source does (ASD repeats them in each strategy appendix). CSQ Part B cross-mapping is deferred to the pre-ASR window (~22 Dec 2026) per project plan. Total requirements: 107. Per-strategy counts: Patch applications=11, Patch operating systems=8, Multi-factor authentication=19, Restrict administrative privileges=20, Application control=14, Restrict Microsoft Office macros=5, User application hardening=22, Regular backups=8. Coverage breakdown: Full=3, Partial=21, Gap=71, Not Applicable=12. Gap severities: {'Low': 1, 'Medium': 32, 'High': 49, 'Critical': 10}. The large Gap cluster reflects that most E8 technical evidence lives in operational tooling (Intune, Entra, Defender, Sentinel) and DISP-project artefacts (SPP, SRA, 2024 Defence Cyber Assessment) rather than the controlled WMS corpus — only TEC-POL-001 (Information Security Policy) and TEC-POL-002 (User Access Management Policy) provide WMS-level evidence. Critical gaps concentrate on phishing-resistant MFA (not deployed) and cybersecurity incident response / ASD reporting (no Cyber Incident Response Plan exists).

Requirements

Showing 107 of 107 requirements

IDClauseRequirementApplicabilityCoverageEvidenceGap
E8-ML2-PA-01ML2-PA-01An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.ApplicableGapHigh
Asset discovery cadence not documented in WMS. Likely covered operationally via Intune device inventory but no controlled documentation. Technical evidence is external (Intune/Entra).
E8-ML2-PA-02ML2-PA-02A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.ApplicableGapHigh
Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).
E8-ML2-PA-03ML2-PA-03A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.ApplicableGapHigh
Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).
E8-ML2-PA-04ML2-PA-04A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.ApplicableGapHigh
Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).
E8-ML2-PA-05ML2-PA-05A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.ApplicableGapHigh
Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).
E8-ML2-PA-06ML2-PA-06Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ApplicableFull
  • TEC-POL-001Information Security Policy commits to patch management (critical/high within 48 hours for internet-facing systems) — aligns with this ML2 control but specific cadence procedure not yet issued (TEC-PRO-001 planned).
E8-ML2-PA-07ML2-PA-07Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ApplicablePartial
  • TEC-POL-001Information Security Policy commits to patch management for internet-facing systems; non-critical two-week cadence not spelled out at control level.
High
Two-week cadence for non-critical online-service vulnerabilities not documented at control level — need implementing procedure.
E8-ML2-PA-08ML2-PA-08Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.ApplicableGapHigh
Application-side patching cadence (Office, browsers, email clients, PDF, security) not documented in WMS. Operationally likely handled via Intune Windows Update for Business and Edge/Chrome auto-update, but not captured in a controlled document.
E8-ML2-PA-09ML2-PA-09Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release.ApplicableGapMedium
Patching cadence for general applications not documented. Westlink cloud-only M365 estate — small 3rd-party app footprint but still in scope. Needs procedure.
E8-ML2-PA-10ML2-PA-10Online services that are no longer supported by vendors are removed.ApplicableGapMedium
No documented process for removing unsupported online services. Operationally likely managed via Entra app governance / Becloudsmart, but not documented in WMS.
E8-ML2-PA-11ML2-PA-11Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.ApplicableGapMedium
No documented process for removing unsupported applications. Likely handled operationally via Intune application management.
E8-ML2-POS-01ML2-POS-01An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.ApplicableGapHigh
Asset discovery for OS scope not documented in WMS. Likely handled via Intune device inventory — not captured in controlled documentation.
E8-ML2-POS-02ML2-POS-02A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.ApplicableGapHigh
Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).
E8-ML2-POS-03ML2-POS-03A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.Not ApplicableNot Applicable
Westlink is cloud-only M365 — no internet-facing servers or internet-facing network devices owned by Westlink. SaaS vendor (Microsoft) responsibility under shared responsibility model.
E8-ML2-POS-04ML2-POS-04A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.ApplicableGapHigh
Workstation OS vulnerability scanning cadence not documented in WMS. Intune + Defender for Endpoint provide this operationally but not documented in a controlled procedure.
E8-ML2-POS-05ML2-POS-05Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary.
E8-ML2-POS-06ML2-POS-06Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary.
E8-ML2-POS-07ML2-POS-07Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.ApplicablePartial
  • TEC-POL-001Information Security Policy commits to patch management generally; workstation one-month cadence not spelled out explicitly.
High
Workstation patching one-month cadence not documented at control level. Intune Windows Update for Business provides this operationally — needs documenting in TEC-PRO-001.
E8-ML2-POS-08ML2-POS-08Operating systems that are no longer supported by vendors are replaced.ApplicableGapMedium
No documented lifecycle for unsupported operating systems. Likely covered operationally by Intune hardware refresh cycle — not documented in WMS.
E8-ML2-MFA-01ML2-MFA-01Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.ApplicableFull
  • TEC-POL-001Information Security Policy mandates MFA for all remote access, cloud services, privileged accounts, and systems processing OFFICIAL:Sensitive.
  • TEC-POL-002User Access Management Policy requires MFA for all users on all cloud services and remote access.
E8-ML2-MFA-02ML2-MFA-02Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires MFA for all users on cloud services; distinction between first-party and third-party services not explicitly addressed.
  • TEC-POL-001 §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA).
Medium
Third-party service MFA enforcement is implicit in the general cloud-services MFA commitment but not separately addressed. Spot-check per-service MFA status (JOSCAR portal, Hellios, etc.) and document exceptions.
E8-ML2-MFA-03ML2-MFA-03Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires MFA broadly on cloud services.
Low
Non-sensitive third-party service MFA not separately called out. Low risk given data sensitivity.
E8-ML2-MFA-04ML2-MFA-04Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.Not ApplicableNot Applicable
Westlink does not operate customer-facing online services that process sensitive customer data. Heavy haulage / project logistics — customer interaction is B2B via email/portal, not a self-service customer application.
E8-ML2-MFA-05ML2-MFA-05Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.Not ApplicableNot Applicable
No third-party online customer services in scope (B2B logistics operations).
E8-ML2-MFA-06ML2-MFA-06Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.Not ApplicableNot Applicable
Westlink does not authenticate customers to its own customer-facing services.
E8-ML2-MFA-07ML2-MFA-07Multi-factor authentication is used to authenticate privileged users of systems.ApplicableFull
  • TEC-POL-001Information Security Policy mandates MFA for privileged accounts.
  • TEC-POL-002User Access Management Policy requires MFA for all users; privileged access restricted to named individuals with enhanced logging.
  • TEC-PRO-002 §System administration / System hardeningMFA for privileged users — all company access requires two-factor authentication; privileged access validated.
E8-ML2-MFA-08ML2-MFA-08Multi-factor authentication is used to authenticate unprivileged users of systems.ApplicableFull
  • TEC-POL-002User Access Management Policy requires MFA for all users on all cloud services.
  • TEC-PRO-002 §System hardeningMFA for unprivileged users — all company access requires a code from an authorised company mobile phone.
E8-ML2-MFA-09ML2-MFA-09Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires MFA; specific factor-type combinations not stipulated.
Medium
Factor-type requirement (have+know or have+know/are) not documented in WMS. Microsoft Authenticator (something you have) + passcode (know) or biometric (are) meets control operationally; needs documenting.
E8-ML2-MFA-10ML2-MFA-10Multi-factor authentication used for authenticating users of online services is phishing-resistant.ApplicableGapCritical
Phishing-resistant MFA (FIDO2, Windows Hello for Business, certificate-based) is NOT currently deployed per Westlink posture summary (Feb 2025) — current MFA is Authenticator push/code which is not phishing-resistant. This will be a likely DISP ASR audit finding within 12 months. Uplift plan required.
E8-ML2-MFA-11ML2-MFA-11Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.Not ApplicableNot Applicable
No customer-facing online services.
E8-ML2-MFA-12ML2-MFA-12Multi-factor authentication used for authenticating users of systems is phishing-resistant.ApplicableGapCritical
Phishing-resistant MFA not deployed. Same gap as ISM-1872 — FIDO2 / Windows Hello for Business uplift required for DISP ASR.
E8-ML2-MFA-13ML2-MFA-13Successful and unsuccessful multi-factor authentication events are centrally logged.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires access logs for all system authentication and authorisation events, retained per ISM guidance.
Medium
Access log commitment exists in TEC-POL-002 but central MFA-event logging not explicitly called out. Entra sign-in logs provide this operationally.
E8-ML2-MFA-14ML2-MFA-14Event logs are protected from unauthorised modification and deletion.ApplicableGapHigh
Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.
E8-ML2-MFA-15ML2-MFA-15Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary.
E8-ML2-MFA-16ML2-MFA-16Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents.ApplicableGapHigh
Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.
E8-ML2-MFA-17ML2-MFA-17Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.ApplicableFull
  • TEC-POL-001Information Security Policy requires reporting all security incidents immediately to the Security Officer.
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-MFA-18ML2-MFA-18Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered.ApplicablePartialHigh
TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.
E8-ML2-MFA-19ML2-MFA-19Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted.ApplicableFull
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-RAP-01ML2-RAP-01Requests for privileged access to systems, applications and data repositories are validated when first requested.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires user accounts to be created only on authorised request with manager approval; privileged access restricted to named individuals.
  • TEC-POL-001 §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA).
Medium
Generic approval requirement is present; specific validation workflow for privileged access (separate approval chain, business-justification artefact, periodic attestation) not documented. Needs procedural uplift.
E8-ML2-RAP-02ML2-RAP-02Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires formal access reviews at least every 12 months for all users, and quarterly for privileged accounts.
  • TEC-POL-001 §Policy CommitmentsInformation Security Policy — commits to access control (need-to-know, MFA).
Medium
12-month review cadence documented; explicit 'disable unless revalidated' enforcement mechanism not spelled out. Operationally covered via Entra access reviews.
E8-ML2-RAP-03ML2-RAP-03Privileged access to systems and applications is disabled after 45 days of inactivity.ApplicableGapHigh
45-day inactivity disable is not documented in any WMS policy. Entra ID policies likely enforce this operationally but need documenting.
E8-ML2-RAP-04ML2-RAP-04Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires privileged access restricted to named individuals; shared or generic accounts are prohibited.
Medium
'Named individuals' and 'no generic accounts' implies dedicated privileged accounts but the two-account model (separate unprivileged daily-use + privileged admin) is not explicitly stated.
E8-ML2-RAP-05ML2-RAP-05Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.ApplicablePartial
  • TEC-PRO-002 §System administrationSecurity controls prevent privileged users from reading email, browsing the web and obtaining files online (enforced via Conditional Access; now documented).
High
Privileged account internet/email restriction not documented. For cloud-only M365, this is enforced via Conditional Access policies scoped to privileged roles — needs documenting as a control.
E8-ML2-RAP-06ML2-RAP-06Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.ApplicablePartial
  • TEC-POL-002User Access Management Policy applies least privilege with role-based access control.
Medium
Least-privilege principle is stated; specific scoping for privileged-user online-service access is not separately addressed.
E8-ML2-RAP-07ML2-RAP-07Privileged users use separate privileged and unprivileged operating environments.ApplicableGapHigh
Separate privileged/unprivileged operating environments (Privileged Access Workstation or similar) not documented. Cloud-only M365 estate — implementation via Microsoft Secure Admin Workstation or Cloud PC is the likely uplift path. Not in place per posture summary.
E8-ML2-RAP-08ML2-RAP-08Privileged operating environments are not virtualised within unprivileged operating environments.ApplicableGapHigh
No documented policy. Dependent on separate privileged OE being implemented first.
E8-ML2-RAP-09ML2-RAP-09Unprivileged user accounts cannot logon to privileged operating environments.ApplicableGapHigh
Not documented. Dependent on separate privileged OE being implemented first.
E8-ML2-RAP-10ML2-RAP-10Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.ApplicableGapHigh
Not documented. Dependent on two-account model being implemented first.
E8-ML2-RAP-11ML2-RAP-11Administrative activities are conducted through jump servers.ApplicableGapMedium
Jump server use not documented. For cloud-only M365 the equivalent control is Microsoft Entra Privileged Identity Management / Azure Bastion for privileged sessions — needs documenting if adopted, or formal risk acceptance if not applicable to the cloud-only model.
E8-ML2-RAP-12ML2-RAP-12Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.ApplicableGapHigh
Break-glass / local admin / service account credential standards not documented. Emergency access account management is a DISP ASR focus — needs explicit control in TEC-POL-002 or a dedicated Privileged Access Standard.
E8-ML2-RAP-13ML2-RAP-13Privileged access events are centrally logged.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires access logs for all system authentication and authorisation events; privileged access subject to enhanced logging.
Medium
Enhanced logging commitment exists; central log retention beyond Entra audit logs is not explicitly addressed (Defender for Cloud Apps / Sentinel integration not documented).
E8-ML2-RAP-14ML2-RAP-14Privileged user account and security group management events are centrally logged.ApplicablePartial
  • TEC-POL-002User Access Management Policy requires access logs for authentication and authorisation events.
Medium
Group-management event logging covered implicitly. Entra audit logs cover this operationally.
E8-ML2-RAP-15ML2-RAP-15Event logs are protected from unauthorised modification and deletion.ApplicableGapHigh
Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.
E8-ML2-RAP-16ML2-RAP-16Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers.
E8-ML2-RAP-17ML2-RAP-17Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents.ApplicableGapHigh
Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.
E8-ML2-RAP-18ML2-RAP-18Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.ApplicableFull
  • TEC-POL-001Information Security Policy requires reporting all security incidents immediately to the Security Officer.
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-RAP-19ML2-RAP-19Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered.ApplicablePartialHigh
TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.
E8-ML2-RAP-20ML2-RAP-20Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted.ApplicableFull
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-AC-01ML2-AC-01Application control is implemented on workstations.ApplicablePartialHigh
Application control (AppLocker / Windows Defender Application Control / WDAC) not documented in WMS. 2024 Defence Cyber Assessment notes application control as 'Embedded' operationally but no WMS documentation exists. Becloudsmart-managed.
E8-ML2-AC-02ML2-AC-02Application control is implemented on internet-facing servers.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers.
E8-ML2-AC-03ML2-AC-03Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.ApplicableGapHigh
Not documented. Dependent on ISM-0843 being documented/verified.
E8-ML2-AC-04ML2-AC-04Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.ApplicableGapHigh
Not documented. Dependent on ISM-0843 being documented/verified.
E8-ML2-AC-05ML2-AC-05Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.ApplicableGapHigh
Approved-application set not documented. Required for both E8 ML2 and ISM — uplift needed.
E8-ML2-AC-06ML2-AC-06Microsoft's recommended application blocklist is implemented.ApplicableGapHigh
Microsoft recommended blocklist implementation not documented. Operationally likely enforced via Defender / WDAC templates — needs confirming and documenting.
E8-ML2-AC-07ML2-AC-07Application control rulesets are validated on an annual or more frequent basis.ApplicableGapMedium
Annual ruleset validation not documented. No application-control ruleset documentation exists — prerequisite is implementing and documenting the ruleset.
E8-ML2-AC-08ML2-AC-08Allowed and blocked application control events are centrally logged.ApplicableGapMedium
Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.
E8-ML2-AC-09ML2-AC-09Event logs are protected from unauthorised modification and deletion.ApplicableGapHigh
Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.
E8-ML2-AC-10ML2-AC-10Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers.
E8-ML2-AC-11ML2-AC-11Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents.ApplicableGapHigh
Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.
E8-ML2-AC-12ML2-AC-12Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.ApplicableFull
  • TEC-POL-001Information Security Policy requires reporting all security incidents immediately to the Security Officer.
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-AC-13ML2-AC-13Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered.ApplicablePartialHigh
TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.
E8-ML2-AC-14ML2-AC-14Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted.ApplicableFull
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity.
E8-ML2-MAC-01ML2-MAC-01Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.ApplicableGapHigh
Office macro restriction not documented in WMS. No policy on Office macro management. Intune / Office admin centre can enforce this — needs documenting.
E8-ML2-MAC-02ML2-MAC-02Microsoft Office macros in files originating from the internet are blocked.ApplicableGapHigh
Internet-sourced macro block not documented. Microsoft's default 'block macros from the internet' policy may be enforced operationally but needs documenting.
E8-ML2-MAC-03ML2-MAC-03Microsoft Office macro antivirus scanning is enabled.ApplicableGapMedium
Macro antivirus scanning not documented. Defender integration likely covers this — needs documenting.
E8-ML2-MAC-04ML2-MAC-04Microsoft Office macros are blocked from making Win32 API calls.ApplicableGapHigh
Win32 API call block for macros not documented. Requires Office ASR rule or equivalent configuration.
E8-ML2-MAC-05ML2-MAC-05Microsoft Office macro security settings cannot be changed by users.ApplicablePartialHigh
User lockdown of macro security settings not documented. Group Policy / Intune Administrative Templates enforce this operationally — needs documenting.
E8-ML2-UAH-01ML2-UAH-01Internet Explorer 11 is disabled or removed.ApplicableGapMedium
IE11 removal not documented. Windows 11 has IE11 disabled by default — needs documenting as a baseline control.
E8-ML2-UAH-02ML2-UAH-02Web browsers do not process Java from the internet.ApplicableGapMedium
Java browser plugin block not documented. Modern browsers (Edge, Chrome) do not support Java plugins by default — needs documenting as a baseline control.
E8-ML2-UAH-03ML2-UAH-03Web browsers do not process web advertisements from the internet.ApplicableGapMedium
Ad-blocking not documented. No enterprise ad-blocker deployment currently. Needs policy decision and deployment.
E8-ML2-UAH-04ML2-UAH-04Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ApplicableGapHigh
Browser hardening baseline not documented. Needs ASD Edge/Chrome hardening guide applied via Intune Administrative Templates.
E8-ML2-UAH-05ML2-UAH-05Web browser security settings cannot be changed by users.ApplicableGapMedium
User lockdown of browser security settings not documented. Intune Administrative Templates enforce this operationally.
E8-ML2-UAH-06ML2-UAH-06Microsoft Office is blocked from creating child processes.ApplicableGapHigh
ASR rule for Office child-process blocking not documented. Attack Surface Reduction rule implementation needed via Intune.
E8-ML2-UAH-07ML2-UAH-07Microsoft Office is blocked from creating executable content.ApplicableGapHigh
ASR rule for Office executable-content blocking not documented.
E8-ML2-UAH-08ML2-UAH-08Microsoft Office is blocked from injecting code into other processes.ApplicableGapHigh
ASR rule for Office code-injection blocking not documented.
E8-ML2-UAH-09ML2-UAH-09Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.ApplicableGapHigh
OLE package activation block not documented.
E8-ML2-UAH-10ML2-UAH-10Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ApplicableGapHigh
Office hardening baseline not documented. ASD M365 hardening guidance not applied in a controlled WMS document.
E8-ML2-UAH-11ML2-UAH-11Office productivity suite security settings cannot be changed by users.ApplicableGapMedium
User lockdown of Office security settings not documented. Intune Administrative Templates enforce this operationally.
E8-ML2-UAH-12ML2-UAH-12PDF software is blocked from creating child processes.ApplicableGapMedium
ASR rule for PDF software not documented. If Adobe Acrobat Reader is used, hardening baseline needed; Edge PDF viewer may be the primary PDF tool in Westlink's estate.
E8-ML2-UAH-13ML2-UAH-13PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ApplicableGapMedium
PDF hardening baseline not documented.
E8-ML2-UAH-14ML2-UAH-14PDF software security settings cannot be changed by users.ApplicableGapMedium
User lockdown of PDF software settings not documented.
E8-ML2-UAH-15ML2-UAH-15PowerShell module logging, script block logging and transcription events are centrally logged.ApplicableGapMedium
PowerShell logging not documented. Intune / Defender for Endpoint / Sentinel integration likely handles this — needs documenting.
E8-ML2-UAH-16ML2-UAH-16Command line process creation events are centrally logged.ApplicableGapMedium
Command-line process creation logging not documented. Defender for Endpoint captures this operationally.
E8-ML2-UAH-17ML2-UAH-17Event logs are protected from unauthorised modification and deletion.ApplicableGapHigh
Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.
E8-ML2-UAH-18ML2-UAH-18Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events.Not ApplicableNot Applicable
Westlink is cloud-only — no internet-facing servers.
E8-ML2-UAH-19ML2-UAH-19Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents.ApplicableGapHigh
Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.
E8-ML2-UAH-20ML2-UAH-20Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.ApplicableFull
  • TEC-POL-001Information Security Policy requires reporting all security incidents immediately to the Security Officer.
  • TEC-PRO-001 §Detection and ReportingTEC-PRO-001 §Detection and Reporting lists detection sources (worker reports, Defender alerts, Entra ID risky sign-in, MSP SOC, ACSC threat intel).
E8-ML2-UAH-21ML2-UAH-21Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered.ApplicablePartialHigh
TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.
E8-ML2-UAH-22ML2-UAH-22Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted.ApplicableFull
  • TEC-PRO-001 §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle (Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity) — the documented enactment of the incident response plan.
E8-ML2-BAK-01ML2-BAK-01Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.ApplicablePartial
  • TEC-POL-001Information Security Policy commits to regular backups with restoration testing as part of ICT security controls aligned with Essential Eight ML2.
High
Backup commitment stated in TEC-POL-001; retention-by-criticality schedule not documented. Microsoft native retention / third-party M365 backup (AvePoint, Veeam, etc.) arrangement not documented in WMS. BCP detail belongs in QHSE-PLN-002 (not yet issued per TEC-POL-001 changelog).
E8-ML2-BAK-02ML2-BAK-02Backups of data, applications and settings are synchronised to enable restoration to a common point in time.ApplicableGapHigh
Common point-in-time restoration not documented. Microsoft 365 native backup is not PIT — needs documented third-party solution or explicit acceptance of Microsoft retention defaults.
E8-ML2-BAK-03ML2-BAK-03Backups of data, applications and settings are retained in a secure and resilient manner.ApplicablePartial
  • TEC-POL-001Information Security Policy references encrypted storage and Microsoft geo-redundant multi-region hosting per organisational context.
Medium
Microsoft geo-redundancy provides resilience; backup-specific secure storage and tamper-resistance not separately addressed. Posture summary notes Microsoft mirrors data across regions — adequate for resilience, but backup-retention-specific security is not documented.
E8-ML2-BAK-04ML2-BAK-04Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.ApplicableGapHigh
Restoration testing from backup as part of DR exercises is NOT documented and likely NOT performed. Backup restore testing is explicitly flagged in the Westlink posture summary as needing documentation/configuration. Uplift: add to QHSE-PLN-002 BCP and establish annual DR test.
E8-ML2-BAK-05ML2-BAK-05Unprivileged user accounts cannot access backups belonging to other user accounts.ApplicableGapMedium
Unprivileged accounts prevented from accessing other accounts' backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart).
E8-ML2-BAK-06ML2-BAK-06Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.ApplicableGapMedium
Backup-administrator role segregation not documented. Dependent on a dedicated backup solution / role being defined.
E8-ML2-BAK-07ML2-BAK-07Unprivileged user accounts are prevented from modifying and deleting backups.ApplicableGapMedium
Unprivileged accounts prevented from modifying/deleting backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart).
E8-ML2-BAK-08ML2-BAK-08Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.ApplicableGapMedium
Privileged-user backup modification restriction not documented. Needs dedicated backup admin role definition.
Source document

Essential Eight Maturity Level 2 — ASD Mitigation Strategies for Westlink Logistics

107 normative shall-statements extracted from Essential Eight Maturity Model — Maturity Level Two (source: ~/projects/DISP/e8_maturity_model.md). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.

Coverage summary

CoverageCount
✅ Full12
🟡 Partial21
🟠 Ref-only0
🔴 Gap62
— N/A12

Gap severity distribution

SeverityCount
🔴 Critical2
🟠 High48
🟡 Medium32
🟢 Low1

Requirements

Clause ML2-AC-01

IDCoverageEvidenceGapNotes
E8-ML2-AC-01🟡 Partial[TEC-PRO-002 §‘System hardening / Responsibilities’](/wms/TEC-PRO-002#s’System hardening / Responsibilities’)🟠 HighApplication control (AppLocker / Windows Defender Application Control / WDAC) not documented in WMS. 2024 Defence Cyber Assessment notes application control as ‘Embedded’ operationally but no WMS documentation exists. Becloudsmart-managed.

Clause ML2-AC-02

IDCoverageEvidenceGapNotes
E8-ML2-AC-02— N/AN/A

Clause ML2-AC-03

IDCoverageEvidenceGapNotes
E8-ML2-AC-03🔴 Gap🟠 HighNot documented. Dependent on ISM-0843 being documented/verified.

Clause ML2-AC-04

IDCoverageEvidenceGapNotes
E8-ML2-AC-04🔴 Gap🟠 HighNot documented. Dependent on ISM-0843 being documented/verified.

Clause ML2-AC-05

IDCoverageEvidenceGapNotes
E8-ML2-AC-05🔴 Gap🟠 HighApproved-application set not documented. Required for both E8 ML2 and ISM — uplift needed.

Clause ML2-AC-06

IDCoverageEvidenceGapNotes
E8-ML2-AC-06🔴 Gap🟠 HighMicrosoft recommended blocklist implementation not documented. Operationally likely enforced via Defender / WDAC templates — needs confirming and documenting.

Clause ML2-AC-07

IDCoverageEvidenceGapNotes
E8-ML2-AC-07🔴 Gap🟡 MediumAnnual ruleset validation not documented. No application-control ruleset documentation exists — prerequisite is implementing and documenting the ruleset.

Clause ML2-AC-08

IDCoverageEvidenceGapNotes
E8-ML2-AC-08🔴 Gap🟡 MediumCentral logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.

Clause ML2-AC-09

IDCoverageEvidenceGapNotes
E8-ML2-AC-09🔴 Gap🟠 HighCentral logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.

Clause ML2-AC-10

IDCoverageEvidenceGapNotes
E8-ML2-AC-10— N/AN/A

Clause ML2-AC-11

IDCoverageEvidenceGapNotes
E8-ML2-AC-11🔴 Gap🟠 HighTimely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.

Clause ML2-AC-12

IDCoverageEvidenceGapNotes
E8-ML2-AC-12✅ FullTEC-POL-001
[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-AC-13

IDCoverageEvidenceGapNotes
E8-ML2-AC-13🟡 Partial[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)🟠 HighTEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.

Clause ML2-AC-14

IDCoverageEvidenceGapNotes
E8-ML2-AC-14✅ Full[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-BAK-01

IDCoverageEvidenceGapNotes
E8-ML2-BAK-01🟡 PartialTEC-POL-001🟠 HighBackup commitment stated in TEC-POL-001; retention-by-criticality schedule not documented. Microsoft native retention / third-party M365 backup (AvePoint, Veeam, etc.) arrangement not documented in WMS. BCP detail belongs in QHSE-PLN-002 (not yet issued per TEC-POL-001 changelog).

Clause ML2-BAK-02

IDCoverageEvidenceGapNotes
E8-ML2-BAK-02🔴 Gap🟠 HighCommon point-in-time restoration not documented. Microsoft 365 native backup is not PIT — needs documented third-party solution or explicit acceptance of Microsoft retention defaults.

Clause ML2-BAK-03

IDCoverageEvidenceGapNotes
E8-ML2-BAK-03🟡 PartialTEC-POL-001🟡 MediumMicrosoft geo-redundancy provides resilience; backup-specific secure storage and tamper-resistance not separately addressed. Posture summary notes Microsoft mirrors data across regions — adequate for resilience, but backup-retention-specific security is not documented.

Clause ML2-BAK-04

IDCoverageEvidenceGapNotes
E8-ML2-BAK-04🔴 Gap🟠 High’Restoration testing from backup as part of DR exercises is NOT documented and likely NOT performed. Backup restore testing is explicitly flagged in the Westlink posture summary as needing documentation/configuration. Uplift: add to QHSE-PLN-002 BCP and establish annual DR test.‘

Clause ML2-BAK-05

IDCoverageEvidenceGapNotes
E8-ML2-BAK-05🔴 Gap🟡 MediumUnprivileged accounts prevented from accessing other accounts’ backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart).

Clause ML2-BAK-06

IDCoverageEvidenceGapNotes
E8-ML2-BAK-06🔴 Gap🟡 MediumBackup-administrator role segregation not documented. Dependent on a dedicated backup solution / role being defined.

Clause ML2-BAK-07

IDCoverageEvidenceGapNotes
E8-ML2-BAK-07🔴 Gap🟡 MediumUnprivileged accounts prevented from modifying/deleting backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart).

Clause ML2-BAK-08

IDCoverageEvidenceGapNotes
E8-ML2-BAK-08🔴 Gap🟡 MediumPrivileged-user backup modification restriction not documented. Needs dedicated backup admin role definition.

Clause ML2-MAC-01

IDCoverageEvidenceGapNotes
E8-ML2-MAC-01🔴 Gap🟠 HighOffice macro restriction not documented in WMS. No policy on Office macro management. Intune / Office admin centre can enforce this — needs documenting.

Clause ML2-MAC-02

IDCoverageEvidenceGapNotes
E8-ML2-MAC-02🔴 Gap🟠 HighInternet-sourced macro block not documented. Microsoft’s default ‘block macros from the internet’ policy may be enforced operationally but needs documenting.

Clause ML2-MAC-03

IDCoverageEvidenceGapNotes
E8-ML2-MAC-03🔴 Gap🟡 MediumMacro antivirus scanning not documented. Defender integration likely covers this — needs documenting.

Clause ML2-MAC-04

IDCoverageEvidenceGapNotes
E8-ML2-MAC-04🔴 Gap🟠 HighWin32 API call block for macros not documented. Requires Office ASR rule or equivalent configuration.

Clause ML2-MAC-05

IDCoverageEvidenceGapNotes
E8-ML2-MAC-05🟡 Partial[TEC-PRO-002 §‘System hardening’](/wms/TEC-PRO-002#s’System hardening’)🟠 HighUser lockdown of macro security settings not documented. Group Policy / Intune Administrative Templates enforce this operationally — needs documenting.

Clause ML2-MFA-01

IDCoverageEvidenceGapNotes
E8-ML2-MFA-01✅ FullTEC-POL-001
TEC-POL-002

Clause ML2-MFA-02

IDCoverageEvidenceGapNotes
E8-ML2-MFA-02🟡 PartialTEC-POL-002
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
🟡 MediumThird-party service MFA enforcement is implicit in the general cloud-services MFA commitment but not separately addressed. Spot-check per-service MFA status (JOSCAR portal, Hellios, etc.) and document exceptions.

Clause ML2-MFA-03

IDCoverageEvidenceGapNotes
E8-ML2-MFA-03🟡 PartialTEC-POL-002🟢 LowNon-sensitive third-party service MFA not separately called out. Low risk given data sensitivity.

Clause ML2-MFA-04

IDCoverageEvidenceGapNotes
E8-ML2-MFA-04— N/AN/A

Clause ML2-MFA-05

IDCoverageEvidenceGapNotes
E8-ML2-MFA-05— N/AN/A

Clause ML2-MFA-06

IDCoverageEvidenceGapNotes
E8-ML2-MFA-06— N/AN/A

Clause ML2-MFA-07

IDCoverageEvidenceGapNotes
E8-ML2-MFA-07✅ FullTEC-POL-001
TEC-POL-002
[TEC-PRO-002 §‘System administration / System hardening’](/wms/TEC-PRO-002#s’System administration / System hardening’)

Clause ML2-MFA-08

IDCoverageEvidenceGapNotes
E8-ML2-MFA-08✅ FullTEC-POL-002
[TEC-PRO-002 §‘System hardening’](/wms/TEC-PRO-002#s’System hardening’)

Clause ML2-MFA-09

IDCoverageEvidenceGapNotes
E8-ML2-MFA-09🟡 PartialTEC-POL-002🟡 MediumFactor-type requirement (have+know or have+know/are) not documented in WMS. Microsoft Authenticator (something you have) + passcode (know) or biometric (are) meets control operationally; needs documenting.

Clause ML2-MFA-10

IDCoverageEvidenceGapNotes
E8-ML2-MFA-10🔴 Gap🔴 CriticalPhishing-resistant MFA (FIDO2, Windows Hello for Business, certificate-based) is NOT currently deployed per Westlink posture summary (Feb 2025) — current MFA is Authenticator push/code which is not phishing-resistant. This will be a likely DISP ASR audit finding within 12 months. Uplift plan required.

Clause ML2-MFA-11

IDCoverageEvidenceGapNotes
E8-ML2-MFA-11— N/AN/A

Clause ML2-MFA-12

IDCoverageEvidenceGapNotes
E8-ML2-MFA-12🔴 Gap🔴 CriticalPhishing-resistant MFA not deployed. Same gap as ISM-1872 — FIDO2 / Windows Hello for Business uplift required for DISP ASR.

Clause ML2-MFA-13

IDCoverageEvidenceGapNotes
E8-ML2-MFA-13🟡 PartialTEC-POL-002🟡 MediumAccess log commitment exists in TEC-POL-002 but central MFA-event logging not explicitly called out. Entra sign-in logs provide this operationally.

Clause ML2-MFA-14

IDCoverageEvidenceGapNotes
E8-ML2-MFA-14🔴 Gap🟠 HighCentral logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.

Clause ML2-MFA-15

IDCoverageEvidenceGapNotes
E8-ML2-MFA-15— N/AN/A

Clause ML2-MFA-16

IDCoverageEvidenceGapNotes
E8-ML2-MFA-16🔴 Gap🟠 HighTimely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.

Clause ML2-MFA-17

IDCoverageEvidenceGapNotes
E8-ML2-MFA-17✅ FullTEC-POL-001
[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-MFA-18

IDCoverageEvidenceGapNotes
E8-ML2-MFA-18🟡 Partial[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)🟠 HighTEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.

Clause ML2-MFA-19

IDCoverageEvidenceGapNotes
E8-ML2-MFA-19✅ Full[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-PA-01

IDCoverageEvidenceGapNotes
E8-ML2-PA-01🔴 Gap🟠 HighAsset discovery cadence not documented in WMS. Likely covered operationally via Intune device inventory but no controlled documentation. Technical evidence is external (Intune/Entra).

Clause ML2-PA-02

IDCoverageEvidenceGapNotes
E8-ML2-PA-02🔴 Gap🟠 HighPatching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).

Clause ML2-PA-03

IDCoverageEvidenceGapNotes
E8-ML2-PA-03🔴 Gap🟠 HighPatching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).

Clause ML2-PA-04

IDCoverageEvidenceGapNotes
E8-ML2-PA-04🔴 Gap🟠 HighPatching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).

Clause ML2-PA-05

IDCoverageEvidenceGapNotes
E8-ML2-PA-05🔴 Gap🟠 HighPatching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).

Clause ML2-PA-06

IDCoverageEvidenceGapNotes
E8-ML2-PA-06✅ FullTEC-POL-001

Clause ML2-PA-07

IDCoverageEvidenceGapNotes
E8-ML2-PA-07🟡 PartialTEC-POL-001🟠 HighTwo-week cadence for non-critical online-service vulnerabilities not documented at control level — need implementing procedure.

Clause ML2-PA-08

IDCoverageEvidenceGapNotes
E8-ML2-PA-08🔴 Gap🟠 HighApplication-side patching cadence (Office, browsers, email clients, PDF, security) not documented in WMS. Operationally likely handled via Intune Windows Update for Business and Edge/Chrome auto-update, but not captured in a controlled document.

Clause ML2-PA-09

IDCoverageEvidenceGapNotes
E8-ML2-PA-09🔴 Gap🟡 MediumPatching cadence for general applications not documented. Westlink cloud-only M365 estate — small 3rd-party app footprint but still in scope. Needs procedure.

Clause ML2-PA-10

IDCoverageEvidenceGapNotes
E8-ML2-PA-10🔴 Gap🟡 MediumNo documented process for removing unsupported online services. Operationally likely managed via Entra app governance / Becloudsmart, but not documented in WMS.

Clause ML2-PA-11

IDCoverageEvidenceGapNotes
E8-ML2-PA-11🔴 Gap🟡 MediumNo documented process for removing unsupported applications. Likely handled operationally via Intune application management.

Clause ML2-POS-01

IDCoverageEvidenceGapNotes
E8-ML2-POS-01🔴 Gap🟠 HighAsset discovery for OS scope not documented in WMS. Likely handled via Intune device inventory — not captured in controlled documentation.

Clause ML2-POS-02

IDCoverageEvidenceGapNotes
E8-ML2-POS-02🔴 Gap🟠 HighPatching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created).

Clause ML2-POS-03

IDCoverageEvidenceGapNotes
E8-ML2-POS-03— N/AN/A

Clause ML2-POS-04

IDCoverageEvidenceGapNotes
E8-ML2-POS-04🔴 Gap🟠 HighWorkstation OS vulnerability scanning cadence not documented in WMS. Intune + Defender for Endpoint provide this operationally but not documented in a controlled procedure.

Clause ML2-POS-05

IDCoverageEvidenceGapNotes
E8-ML2-POS-05— N/AN/A

Clause ML2-POS-06

IDCoverageEvidenceGapNotes
E8-ML2-POS-06— N/AN/A

Clause ML2-POS-07

IDCoverageEvidenceGapNotes
E8-ML2-POS-07🟡 PartialTEC-POL-001🟠 HighWorkstation patching one-month cadence not documented at control level. Intune Windows Update for Business provides this operationally — needs documenting in TEC-PRO-001.

Clause ML2-POS-08

IDCoverageEvidenceGapNotes
E8-ML2-POS-08🔴 Gap🟡 MediumNo documented lifecycle for unsupported operating systems. Likely covered operationally by Intune hardware refresh cycle — not documented in WMS.

Clause ML2-RAP-01

IDCoverageEvidenceGapNotes
E8-ML2-RAP-01🟡 PartialTEC-POL-002
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
🟡 MediumGeneric approval requirement is present; specific validation workflow for privileged access (separate approval chain, business-justification artefact, periodic attestation) not documented. Needs procedural uplift.

Clause ML2-RAP-02

IDCoverageEvidenceGapNotes
E8-ML2-RAP-02🟡 PartialTEC-POL-002
[TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments)
🟡 Medium12-month review cadence documented; explicit ‘disable unless revalidated’ enforcement mechanism not spelled out. Operationally covered via Entra access reviews.

Clause ML2-RAP-03

IDCoverageEvidenceGapNotes
E8-ML2-RAP-03🔴 Gap🟠 High45-day inactivity disable is not documented in any WMS policy. Entra ID policies likely enforce this operationally but need documenting.

Clause ML2-RAP-04

IDCoverageEvidenceGapNotes
E8-ML2-RAP-04🟡 PartialTEC-POL-002🟡 Medium’Named individuals’ and ‘no generic accounts’ implies dedicated privileged accounts but the two-account model (separate unprivileged daily-use + privileged admin) is not explicitly stated.

Clause ML2-RAP-05

IDCoverageEvidenceGapNotes
E8-ML2-RAP-05🟡 Partial[TEC-PRO-002 §‘System administration’](/wms/TEC-PRO-002#s’System administration’)🟠 HighPrivileged account internet/email restriction not documented. For cloud-only M365, this is enforced via Conditional Access policies scoped to privileged roles — needs documenting as a control.

Clause ML2-RAP-06

IDCoverageEvidenceGapNotes
E8-ML2-RAP-06🟡 PartialTEC-POL-002🟡 MediumLeast-privilege principle is stated; specific scoping for privileged-user online-service access is not separately addressed.

Clause ML2-RAP-07

IDCoverageEvidenceGapNotes
E8-ML2-RAP-07🔴 Gap🟠 HighSeparate privileged/unprivileged operating environments (Privileged Access Workstation or similar) not documented. Cloud-only M365 estate — implementation via Microsoft Secure Admin Workstation or Cloud PC is the likely uplift path. Not in place per posture summary.

Clause ML2-RAP-08

IDCoverageEvidenceGapNotes
E8-ML2-RAP-08🔴 Gap🟠 HighNo documented policy. Dependent on separate privileged OE being implemented first.

Clause ML2-RAP-09

IDCoverageEvidenceGapNotes
E8-ML2-RAP-09🔴 Gap🟠 HighNot documented. Dependent on separate privileged OE being implemented first.

Clause ML2-RAP-10

IDCoverageEvidenceGapNotes
E8-ML2-RAP-10🔴 Gap🟠 HighNot documented. Dependent on two-account model being implemented first.

Clause ML2-RAP-11

IDCoverageEvidenceGapNotes
E8-ML2-RAP-11🔴 Gap🟡 MediumJump server use not documented. For cloud-only M365 the equivalent control is Microsoft Entra Privileged Identity Management / Azure Bastion for privileged sessions — needs documenting if adopted, or formal risk acceptance if not applicable to the cloud-only model.

Clause ML2-RAP-12

IDCoverageEvidenceGapNotes
E8-ML2-RAP-12🔴 Gap🟠 HighBreak-glass / local admin / service account credential standards not documented. Emergency access account management is a DISP ASR focus — needs explicit control in TEC-POL-002 or a dedicated Privileged Access Standard.

Clause ML2-RAP-13

IDCoverageEvidenceGapNotes
E8-ML2-RAP-13🟡 PartialTEC-POL-002🟡 MediumEnhanced logging commitment exists; central log retention beyond Entra audit logs is not explicitly addressed (Defender for Cloud Apps / Sentinel integration not documented).

Clause ML2-RAP-14

IDCoverageEvidenceGapNotes
E8-ML2-RAP-14🟡 PartialTEC-POL-002🟡 MediumGroup-management event logging covered implicitly. Entra audit logs cover this operationally.

Clause ML2-RAP-15

IDCoverageEvidenceGapNotes
E8-ML2-RAP-15🔴 Gap🟠 HighCentral logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.

Clause ML2-RAP-16

IDCoverageEvidenceGapNotes
E8-ML2-RAP-16— N/AN/A

Clause ML2-RAP-17

IDCoverageEvidenceGapNotes
E8-ML2-RAP-17🔴 Gap🟠 HighTimely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.

Clause ML2-RAP-18

IDCoverageEvidenceGapNotes
E8-ML2-RAP-18✅ FullTEC-POL-001
[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-RAP-19

IDCoverageEvidenceGapNotes
E8-ML2-RAP-19🟡 Partial[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)🟠 HighTEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.

Clause ML2-RAP-20

IDCoverageEvidenceGapNotes
E8-ML2-RAP-20✅ Full[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Clause ML2-UAH-01

IDCoverageEvidenceGapNotes
E8-ML2-UAH-01🔴 Gap🟡 MediumIE11 removal not documented. Windows 11 has IE11 disabled by default — needs documenting as a baseline control.

Clause ML2-UAH-02

IDCoverageEvidenceGapNotes
E8-ML2-UAH-02🔴 Gap🟡 MediumJava browser plugin block not documented. Modern browsers (Edge, Chrome) do not support Java plugins by default — needs documenting as a baseline control.

Clause ML2-UAH-03

IDCoverageEvidenceGapNotes
E8-ML2-UAH-03🔴 Gap🟡 MediumAd-blocking not documented. No enterprise ad-blocker deployment currently. Needs policy decision and deployment.

Clause ML2-UAH-04

IDCoverageEvidenceGapNotes
E8-ML2-UAH-04🔴 Gap🟠 HighBrowser hardening baseline not documented. Needs ASD Edge/Chrome hardening guide applied via Intune Administrative Templates.

Clause ML2-UAH-05

IDCoverageEvidenceGapNotes
E8-ML2-UAH-05🔴 Gap🟡 MediumUser lockdown of browser security settings not documented. Intune Administrative Templates enforce this operationally.

Clause ML2-UAH-06

IDCoverageEvidenceGapNotes
E8-ML2-UAH-06🔴 Gap🟠 HighASR rule for Office child-process blocking not documented. Attack Surface Reduction rule implementation needed via Intune.

Clause ML2-UAH-07

IDCoverageEvidenceGapNotes
E8-ML2-UAH-07🔴 Gap🟠 HighASR rule for Office executable-content blocking not documented.

Clause ML2-UAH-08

IDCoverageEvidenceGapNotes
E8-ML2-UAH-08🔴 Gap🟠 HighASR rule for Office code-injection blocking not documented.

Clause ML2-UAH-09

IDCoverageEvidenceGapNotes
E8-ML2-UAH-09🔴 Gap🟠 HighOLE package activation block not documented.

Clause ML2-UAH-10

IDCoverageEvidenceGapNotes
E8-ML2-UAH-10🔴 Gap🟠 HighOffice hardening baseline not documented. ASD M365 hardening guidance not applied in a controlled WMS document.

Clause ML2-UAH-11

IDCoverageEvidenceGapNotes
E8-ML2-UAH-11🔴 Gap🟡 MediumUser lockdown of Office security settings not documented. Intune Administrative Templates enforce this operationally.

Clause ML2-UAH-12

IDCoverageEvidenceGapNotes
E8-ML2-UAH-12🔴 Gap🟡 MediumASR rule for PDF software not documented. If Adobe Acrobat Reader is used, hardening baseline needed; Edge PDF viewer may be the primary PDF tool in Westlink’s estate.

Clause ML2-UAH-13

IDCoverageEvidenceGapNotes
E8-ML2-UAH-13🔴 Gap🟡 MediumPDF hardening baseline not documented.

Clause ML2-UAH-14

IDCoverageEvidenceGapNotes
E8-ML2-UAH-14🔴 Gap🟡 MediumUser lockdown of PDF software settings not documented.

Clause ML2-UAH-15

IDCoverageEvidenceGapNotes
E8-ML2-UAH-15🔴 Gap🟡 MediumPowerShell logging not documented. Intune / Defender for Endpoint / Sentinel integration likely handles this — needs documenting.

Clause ML2-UAH-16

IDCoverageEvidenceGapNotes
E8-ML2-UAH-16🔴 Gap🟡 MediumCommand-line process creation logging not documented. Defender for Endpoint captures this operationally.

Clause ML2-UAH-17

IDCoverageEvidenceGapNotes
E8-ML2-UAH-17🔴 Gap🟠 HighCentral logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus.

Clause ML2-UAH-18

IDCoverageEvidenceGapNotes
E8-ML2-UAH-18— N/AN/A

Clause ML2-UAH-19

IDCoverageEvidenceGapNotes
E8-ML2-UAH-19🔴 Gap🟠 HighTimely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure.

Clause ML2-UAH-20

IDCoverageEvidenceGapNotes
E8-ML2-UAH-20✅ FullTEC-POL-001
[TEC-PRO-001 §‘Detection and Reporting’](/wms/TEC-PRO-001#s’Detection and Reporting’)

Clause ML2-UAH-21

IDCoverageEvidenceGapNotes
E8-ML2-UAH-21🟡 Partial[TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’)🟠 HighTEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70.

Clause ML2-UAH-22

IDCoverageEvidenceGapNotes
E8-ML2-UAH-22✅ Full[TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’)

Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.