Essential Eight Maturity Model — Maturity Level Two
Essential Eight Maturity Level 2 — ASD Mitigation Strategies for Westlink Logistics
- Requirements
- 107
- Last reviewed
- 15/04/2026
- Next review
- 15/04/2027
- Source
- ASD Essential Eight Maturity Model, November 2023
Reconciliation notes
E8 ML2 compliance library is a curated build because the source is a PDF-converted markdown (ASD Essential Eight Maturity Model, November 2023), not an EPUB with numbered clauses. All 8 mitigation strategies are captured at ML2 only — ML1 and ML3 are out of scope for this file. Shared logging / cybersecurity-event-analysis / incident-reporting / IR-plan controls are captured per-strategy as the source does (ASD repeats them in each strategy appendix). CSQ Part B cross-mapping is deferred to the pre-ASR window (~22 Dec 2026) per project plan. Total requirements: 107. Per-strategy counts: Patch applications=11, Patch operating systems=8, Multi-factor authentication=19, Restrict administrative privileges=20, Application control=14, Restrict Microsoft Office macros=5, User application hardening=22, Regular backups=8. Coverage breakdown: Full=3, Partial=21, Gap=71, Not Applicable=12. Gap severities: {'Low': 1, 'Medium': 32, 'High': 49, 'Critical': 10}. The large Gap cluster reflects that most E8 technical evidence lives in operational tooling (Intune, Entra, Defender, Sentinel) and DISP-project artefacts (SPP, SRA, 2024 Defence Cyber Assessment) rather than the controlled WMS corpus — only TEC-POL-001 (Information Security Policy) and TEC-POL-002 (User Access Management Policy) provide WMS-level evidence. Critical gaps concentrate on phishing-resistant MFA (not deployed) and cybersecurity incident response / ASD reporting (no Cyber Incident Response Plan exists).
Requirements
Showing 107 of 107 requirements
| ID | Clause | Requirement | Applicability | Coverage | Evidence | Gap |
|---|---|---|---|---|---|---|
| E8-ML2-PA-01 | ML2-PA-01 | An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. | Applicable | Gap | — | High Asset discovery cadence not documented in WMS. Likely covered operationally via Intune device inventory but no controlled documentation. Technical evidence is external (Intune/Entra). |
| E8-ML2-PA-02 | ML2-PA-02 | A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. | Applicable | Gap | — | High Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
| E8-ML2-PA-03 | ML2-PA-03 | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services. | Applicable | Gap | — | High Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
| E8-ML2-PA-04 | ML2-PA-04 | A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. | Applicable | Gap | — | High Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
| E8-ML2-PA-05 | ML2-PA-05 | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products. | Applicable | Gap | — | High Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
| E8-ML2-PA-06 | ML2-PA-06 | Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. | Applicable | Full |
| |
| E8-ML2-PA-07 | ML2-PA-07 | Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. | Applicable | Partial |
| High Two-week cadence for non-critical online-service vulnerabilities not documented at control level — need implementing procedure. |
| E8-ML2-PA-08 | ML2-PA-08 | Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release. | Applicable | Gap | — | High Application-side patching cadence (Office, browsers, email clients, PDF, security) not documented in WMS. Operationally likely handled via Intune Windows Update for Business and Edge/Chrome auto-update, but not captured in a controlled document. |
| E8-ML2-PA-09 | ML2-PA-09 | Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release. | Applicable | Gap | — | Medium Patching cadence for general applications not documented. Westlink cloud-only M365 estate — small 3rd-party app footprint but still in scope. Needs procedure. |
| E8-ML2-PA-10 | ML2-PA-10 | Online services that are no longer supported by vendors are removed. | Applicable | Gap | — | Medium No documented process for removing unsupported online services. Operationally likely managed via Entra app governance / Becloudsmart, but not documented in WMS. |
| E8-ML2-PA-11 | ML2-PA-11 | Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. | Applicable | Gap | — | Medium No documented process for removing unsupported applications. Likely handled operationally via Intune application management. |
| E8-ML2-POS-01 | ML2-POS-01 | An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities. | Applicable | Gap | — | High Asset discovery for OS scope not documented in WMS. Likely handled via Intune device inventory — not captured in controlled documentation. |
| E8-ML2-POS-02 | ML2-POS-02 | A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities. | Applicable | Gap | — | High Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
| E8-ML2-POS-03 | ML2-POS-03 | A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices. | Not Applicable | Not Applicable | — | Westlink is cloud-only M365 — no internet-facing servers or internet-facing network devices owned by Westlink. SaaS vendor (Microsoft) responsibility under shared responsibility model. |
| E8-ML2-POS-04 | ML2-POS-04 | A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices. | Applicable | Gap | — | High Workstation OS vulnerability scanning cadence not documented in WMS. Intune + Defender for Endpoint provide this operationally but not documented in a controlled procedure. |
| E8-ML2-POS-05 | ML2-POS-05 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary. |
| E8-ML2-POS-06 | ML2-POS-06 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary. |
| E8-ML2-POS-07 | ML2-POS-07 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release. | Applicable | Partial |
| High Workstation patching one-month cadence not documented at control level. Intune Windows Update for Business provides this operationally — needs documenting in TEC-PRO-001. |
| E8-ML2-POS-08 | ML2-POS-08 | Operating systems that are no longer supported by vendors are replaced. | Applicable | Gap | — | Medium No documented lifecycle for unsupported operating systems. Likely covered operationally by Intune hardware refresh cycle — not documented in WMS. |
| E8-ML2-MFA-01 | ML2-MFA-01 | Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data. | Applicable | Full |
| |
| E8-ML2-MFA-02 | ML2-MFA-02 | Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data. | Applicable | Partial |
| Medium Third-party service MFA enforcement is implicit in the general cloud-services MFA commitment but not separately addressed. Spot-check per-service MFA status (JOSCAR portal, Hellios, etc.) and document exceptions. |
| E8-ML2-MFA-03 | ML2-MFA-03 | Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data. | Applicable | Partial |
| Low Non-sensitive third-party service MFA not separately called out. Low risk given data sensitivity. |
| E8-ML2-MFA-04 | ML2-MFA-04 | Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data. | Not Applicable | Not Applicable | — | Westlink does not operate customer-facing online services that process sensitive customer data. Heavy haulage / project logistics — customer interaction is B2B via email/portal, not a self-service customer application. |
| E8-ML2-MFA-05 | ML2-MFA-05 | Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data. | Not Applicable | Not Applicable | — | No third-party online customer services in scope (B2B logistics operations). |
| E8-ML2-MFA-06 | ML2-MFA-06 | Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data. | Not Applicable | Not Applicable | — | Westlink does not authenticate customers to its own customer-facing services. |
| E8-ML2-MFA-07 | ML2-MFA-07 | Multi-factor authentication is used to authenticate privileged users of systems. | Applicable | Full |
| |
| E8-ML2-MFA-08 | ML2-MFA-08 | Multi-factor authentication is used to authenticate unprivileged users of systems. | Applicable | Full |
| |
| E8-ML2-MFA-09 | ML2-MFA-09 | Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are. | Applicable | Partial |
| Medium Factor-type requirement (have+know or have+know/are) not documented in WMS. Microsoft Authenticator (something you have) + passcode (know) or biometric (are) meets control operationally; needs documenting. |
| E8-ML2-MFA-10 | ML2-MFA-10 | Multi-factor authentication used for authenticating users of online services is phishing-resistant. | Applicable | Gap | — | Critical Phishing-resistant MFA (FIDO2, Windows Hello for Business, certificate-based) is NOT currently deployed per Westlink posture summary (Feb 2025) — current MFA is Authenticator push/code which is not phishing-resistant. This will be a likely DISP ASR audit finding within 12 months. Uplift plan required. |
| E8-ML2-MFA-11 | ML2-MFA-11 | Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option. | Not Applicable | Not Applicable | — | No customer-facing online services. |
| E8-ML2-MFA-12 | ML2-MFA-12 | Multi-factor authentication used for authenticating users of systems is phishing-resistant. | Applicable | Gap | — | Critical Phishing-resistant MFA not deployed. Same gap as ISM-1872 — FIDO2 / Windows Hello for Business uplift required for DISP ASR. |
| E8-ML2-MFA-13 | ML2-MFA-13 | Successful and unsuccessful multi-factor authentication events are centrally logged. | Applicable | Partial |
| Medium Access log commitment exists in TEC-POL-002 but central MFA-event logging not explicitly called out. Entra sign-in logs provide this operationally. |
| E8-ML2-MFA-14 | ML2-MFA-14 | Event logs are protected from unauthorised modification and deletion. | Applicable | Gap | — | High Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
| E8-ML2-MFA-15 | ML2-MFA-15 | Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. Microsoft shared-responsibility boundary. |
| E8-ML2-MFA-16 | ML2-MFA-16 | Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents. | Applicable | Gap | — | High Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
| E8-ML2-MFA-17 | ML2-MFA-17 | Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered. | Applicable | Full |
| |
| E8-ML2-MFA-18 | ML2-MFA-18 | Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered. | Applicable | Partial |
| High TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
| E8-ML2-MFA-19 | ML2-MFA-19 | Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted. | Applicable | Full |
| |
| E8-ML2-RAP-01 | ML2-RAP-01 | Requests for privileged access to systems, applications and data repositories are validated when first requested. | Applicable | Partial |
| Medium Generic approval requirement is present; specific validation workflow for privileged access (separate approval chain, business-justification artefact, periodic attestation) not documented. Needs procedural uplift. |
| E8-ML2-RAP-02 | ML2-RAP-02 | Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. | Applicable | Partial |
| Medium 12-month review cadence documented; explicit 'disable unless revalidated' enforcement mechanism not spelled out. Operationally covered via Entra access reviews. |
| E8-ML2-RAP-03 | ML2-RAP-03 | Privileged access to systems and applications is disabled after 45 days of inactivity. | Applicable | Gap | — | High 45-day inactivity disable is not documented in any WMS policy. Entra ID policies likely enforce this operationally but need documenting. |
| E8-ML2-RAP-04 | ML2-RAP-04 | Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access. | Applicable | Partial |
| Medium 'Named individuals' and 'no generic accounts' implies dedicated privileged accounts but the two-account model (separate unprivileged daily-use + privileged admin) is not explicitly stated. |
| E8-ML2-RAP-05 | ML2-RAP-05 | Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services. | Applicable | Partial |
| High Privileged account internet/email restriction not documented. For cloud-only M365, this is enforced via Conditional Access policies scoped to privileged roles — needs documenting as a control. |
| E8-ML2-RAP-06 | ML2-RAP-06 | Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties. | Applicable | Partial |
| Medium Least-privilege principle is stated; specific scoping for privileged-user online-service access is not separately addressed. |
| E8-ML2-RAP-07 | ML2-RAP-07 | Privileged users use separate privileged and unprivileged operating environments. | Applicable | Gap | — | High Separate privileged/unprivileged operating environments (Privileged Access Workstation or similar) not documented. Cloud-only M365 estate — implementation via Microsoft Secure Admin Workstation or Cloud PC is the likely uplift path. Not in place per posture summary. |
| E8-ML2-RAP-08 | ML2-RAP-08 | Privileged operating environments are not virtualised within unprivileged operating environments. | Applicable | Gap | — | High No documented policy. Dependent on separate privileged OE being implemented first. |
| E8-ML2-RAP-09 | ML2-RAP-09 | Unprivileged user accounts cannot logon to privileged operating environments. | Applicable | Gap | — | High Not documented. Dependent on separate privileged OE being implemented first. |
| E8-ML2-RAP-10 | ML2-RAP-10 | Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments. | Applicable | Gap | — | High Not documented. Dependent on two-account model being implemented first. |
| E8-ML2-RAP-11 | ML2-RAP-11 | Administrative activities are conducted through jump servers. | Applicable | Gap | — | Medium Jump server use not documented. For cloud-only M365 the equivalent control is Microsoft Entra Privileged Identity Management / Azure Bastion for privileged sessions — needs documenting if adopted, or formal risk acceptance if not applicable to the cloud-only model. |
| E8-ML2-RAP-12 | ML2-RAP-12 | Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed. | Applicable | Gap | — | High Break-glass / local admin / service account credential standards not documented. Emergency access account management is a DISP ASR focus — needs explicit control in TEC-POL-002 or a dedicated Privileged Access Standard. |
| E8-ML2-RAP-13 | ML2-RAP-13 | Privileged access events are centrally logged. | Applicable | Partial |
| Medium Enhanced logging commitment exists; central log retention beyond Entra audit logs is not explicitly addressed (Defender for Cloud Apps / Sentinel integration not documented). |
| E8-ML2-RAP-14 | ML2-RAP-14 | Privileged user account and security group management events are centrally logged. | Applicable | Partial |
| Medium Group-management event logging covered implicitly. Entra audit logs cover this operationally. |
| E8-ML2-RAP-15 | ML2-RAP-15 | Event logs are protected from unauthorised modification and deletion. | Applicable | Gap | — | High Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
| E8-ML2-RAP-16 | ML2-RAP-16 | Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. |
| E8-ML2-RAP-17 | ML2-RAP-17 | Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents. | Applicable | Gap | — | High Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
| E8-ML2-RAP-18 | ML2-RAP-18 | Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered. | Applicable | Full |
| |
| E8-ML2-RAP-19 | ML2-RAP-19 | Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered. | Applicable | Partial |
| High TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
| E8-ML2-RAP-20 | ML2-RAP-20 | Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted. | Applicable | Full |
| |
| E8-ML2-AC-01 | ML2-AC-01 | Application control is implemented on workstations. | Applicable | Partial |
| High Application control (AppLocker / Windows Defender Application Control / WDAC) not documented in WMS. 2024 Defence Cyber Assessment notes application control as 'Embedded' operationally but no WMS documentation exists. Becloudsmart-managed. |
| E8-ML2-AC-02 | ML2-AC-02 | Application control is implemented on internet-facing servers. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. |
| E8-ML2-AC-03 | ML2-AC-03 | Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. | Applicable | Gap | — | High Not documented. Dependent on ISM-0843 being documented/verified. |
| E8-ML2-AC-04 | ML2-AC-04 | Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients. | Applicable | Gap | — | High Not documented. Dependent on ISM-0843 being documented/verified. |
| E8-ML2-AC-05 | ML2-AC-05 | Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set. | Applicable | Gap | — | High Approved-application set not documented. Required for both E8 ML2 and ISM — uplift needed. |
| E8-ML2-AC-06 | ML2-AC-06 | Microsoft's recommended application blocklist is implemented. | Applicable | Gap | — | High Microsoft recommended blocklist implementation not documented. Operationally likely enforced via Defender / WDAC templates — needs confirming and documenting. |
| E8-ML2-AC-07 | ML2-AC-07 | Application control rulesets are validated on an annual or more frequent basis. | Applicable | Gap | — | Medium Annual ruleset validation not documented. No application-control ruleset documentation exists — prerequisite is implementing and documenting the ruleset. |
| E8-ML2-AC-08 | ML2-AC-08 | Allowed and blocked application control events are centrally logged. | Applicable | Gap | — | Medium Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
| E8-ML2-AC-09 | ML2-AC-09 | Event logs are protected from unauthorised modification and deletion. | Applicable | Gap | — | High Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
| E8-ML2-AC-10 | ML2-AC-10 | Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. |
| E8-ML2-AC-11 | ML2-AC-11 | Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents. | Applicable | Gap | — | High Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
| E8-ML2-AC-12 | ML2-AC-12 | Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered. | Applicable | Full |
| |
| E8-ML2-AC-13 | ML2-AC-13 | Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered. | Applicable | Partial |
| High TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
| E8-ML2-AC-14 | ML2-AC-14 | Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted. | Applicable | Full |
| |
| E8-ML2-MAC-01 | ML2-MAC-01 | Microsoft Office macros are disabled for users that do not have a demonstrated business requirement. | Applicable | Gap | — | High Office macro restriction not documented in WMS. No policy on Office macro management. Intune / Office admin centre can enforce this — needs documenting. |
| E8-ML2-MAC-02 | ML2-MAC-02 | Microsoft Office macros in files originating from the internet are blocked. | Applicable | Gap | — | High Internet-sourced macro block not documented. Microsoft's default 'block macros from the internet' policy may be enforced operationally but needs documenting. |
| E8-ML2-MAC-03 | ML2-MAC-03 | Microsoft Office macro antivirus scanning is enabled. | Applicable | Gap | — | Medium Macro antivirus scanning not documented. Defender integration likely covers this — needs documenting. |
| E8-ML2-MAC-04 | ML2-MAC-04 | Microsoft Office macros are blocked from making Win32 API calls. | Applicable | Gap | — | High Win32 API call block for macros not documented. Requires Office ASR rule or equivalent configuration. |
| E8-ML2-MAC-05 | ML2-MAC-05 | Microsoft Office macro security settings cannot be changed by users. | Applicable | Partial |
| High User lockdown of macro security settings not documented. Group Policy / Intune Administrative Templates enforce this operationally — needs documenting. |
| E8-ML2-UAH-01 | ML2-UAH-01 | Internet Explorer 11 is disabled or removed. | Applicable | Gap | — | Medium IE11 removal not documented. Windows 11 has IE11 disabled by default — needs documenting as a baseline control. |
| E8-ML2-UAH-02 | ML2-UAH-02 | Web browsers do not process Java from the internet. | Applicable | Gap | — | Medium Java browser plugin block not documented. Modern browsers (Edge, Chrome) do not support Java plugins by default — needs documenting as a baseline control. |
| E8-ML2-UAH-03 | ML2-UAH-03 | Web browsers do not process web advertisements from the internet. | Applicable | Gap | — | Medium Ad-blocking not documented. No enterprise ad-blocker deployment currently. Needs policy decision and deployment. |
| E8-ML2-UAH-04 | ML2-UAH-04 | Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. | Applicable | Gap | — | High Browser hardening baseline not documented. Needs ASD Edge/Chrome hardening guide applied via Intune Administrative Templates. |
| E8-ML2-UAH-05 | ML2-UAH-05 | Web browser security settings cannot be changed by users. | Applicable | Gap | — | Medium User lockdown of browser security settings not documented. Intune Administrative Templates enforce this operationally. |
| E8-ML2-UAH-06 | ML2-UAH-06 | Microsoft Office is blocked from creating child processes. | Applicable | Gap | — | High ASR rule for Office child-process blocking not documented. Attack Surface Reduction rule implementation needed via Intune. |
| E8-ML2-UAH-07 | ML2-UAH-07 | Microsoft Office is blocked from creating executable content. | Applicable | Gap | — | High ASR rule for Office executable-content blocking not documented. |
| E8-ML2-UAH-08 | ML2-UAH-08 | Microsoft Office is blocked from injecting code into other processes. | Applicable | Gap | — | High ASR rule for Office code-injection blocking not documented. |
| E8-ML2-UAH-09 | ML2-UAH-09 | Microsoft Office is configured to prevent activation of Object Linking and Embedding packages. | Applicable | Gap | — | High OLE package activation block not documented. |
| E8-ML2-UAH-10 | ML2-UAH-10 | Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. | Applicable | Gap | — | High Office hardening baseline not documented. ASD M365 hardening guidance not applied in a controlled WMS document. |
| E8-ML2-UAH-11 | ML2-UAH-11 | Office productivity suite security settings cannot be changed by users. | Applicable | Gap | — | Medium User lockdown of Office security settings not documented. Intune Administrative Templates enforce this operationally. |
| E8-ML2-UAH-12 | ML2-UAH-12 | PDF software is blocked from creating child processes. | Applicable | Gap | — | Medium ASR rule for PDF software not documented. If Adobe Acrobat Reader is used, hardening baseline needed; Edge PDF viewer may be the primary PDF tool in Westlink's estate. |
| E8-ML2-UAH-13 | ML2-UAH-13 | PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. | Applicable | Gap | — | Medium PDF hardening baseline not documented. |
| E8-ML2-UAH-14 | ML2-UAH-14 | PDF software security settings cannot be changed by users. | Applicable | Gap | — | Medium User lockdown of PDF software settings not documented. |
| E8-ML2-UAH-15 | ML2-UAH-15 | PowerShell module logging, script block logging and transcription events are centrally logged. | Applicable | Gap | — | Medium PowerShell logging not documented. Intune / Defender for Endpoint / Sentinel integration likely handles this — needs documenting. |
| E8-ML2-UAH-16 | ML2-UAH-16 | Command line process creation events are centrally logged. | Applicable | Gap | — | Medium Command-line process creation logging not documented. Defender for Endpoint captures this operationally. |
| E8-ML2-UAH-17 | ML2-UAH-17 | Event logs are protected from unauthorised modification and deletion. | Applicable | Gap | — | High Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
| E8-ML2-UAH-18 | ML2-UAH-18 | Event logs from internet-facing servers are analysed in a timely manner to detect cybersecurity events. | Not Applicable | Not Applicable | — | Westlink is cloud-only — no internet-facing servers. |
| E8-ML2-UAH-19 | ML2-UAH-19 | Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents. | Applicable | Gap | — | High Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
| E8-ML2-UAH-20 | ML2-UAH-20 | Cybersecurity incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered. | Applicable | Full |
| |
| E8-ML2-UAH-21 | ML2-UAH-21 | Cybersecurity incidents are reported to ASD as soon as possible after they occur or are discovered. | Applicable | Partial |
| High TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
| E8-ML2-UAH-22 | ML2-UAH-22 | Following the identification of a cybersecurity incident, the cybersecurity incident response plan is enacted. | Applicable | Full |
| |
| E8-ML2-BAK-01 | ML2-BAK-01 | Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements. | Applicable | Partial |
| High Backup commitment stated in TEC-POL-001; retention-by-criticality schedule not documented. Microsoft native retention / third-party M365 backup (AvePoint, Veeam, etc.) arrangement not documented in WMS. BCP detail belongs in QHSE-PLN-002 (not yet issued per TEC-POL-001 changelog). |
| E8-ML2-BAK-02 | ML2-BAK-02 | Backups of data, applications and settings are synchronised to enable restoration to a common point in time. | Applicable | Gap | — | High Common point-in-time restoration not documented. Microsoft 365 native backup is not PIT — needs documented third-party solution or explicit acceptance of Microsoft retention defaults. |
| E8-ML2-BAK-03 | ML2-BAK-03 | Backups of data, applications and settings are retained in a secure and resilient manner. | Applicable | Partial |
| Medium Microsoft geo-redundancy provides resilience; backup-specific secure storage and tamper-resistance not separately addressed. Posture summary notes Microsoft mirrors data across regions — adequate for resilience, but backup-retention-specific security is not documented. |
| E8-ML2-BAK-04 | ML2-BAK-04 | Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises. | Applicable | Gap | — | High Restoration testing from backup as part of DR exercises is NOT documented and likely NOT performed. Backup restore testing is explicitly flagged in the Westlink posture summary as needing documentation/configuration. Uplift: add to QHSE-PLN-002 BCP and establish annual DR test. |
| E8-ML2-BAK-05 | ML2-BAK-05 | Unprivileged user accounts cannot access backups belonging to other user accounts. | Applicable | Gap | — | Medium Unprivileged accounts prevented from accessing other accounts' backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart). |
| E8-ML2-BAK-06 | ML2-BAK-06 | Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts. | Applicable | Gap | — | Medium Backup-administrator role segregation not documented. Dependent on a dedicated backup solution / role being defined. |
| E8-ML2-BAK-07 | ML2-BAK-07 | Unprivileged user accounts are prevented from modifying and deleting backups. | Applicable | Gap | — | Medium Unprivileged accounts prevented from modifying/deleting backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart). |
| E8-ML2-BAK-08 | ML2-BAK-08 | Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups. | Applicable | Gap | — | Medium Privileged-user backup modification restriction not documented. Needs dedicated backup admin role definition. |
Source document
Essential Eight Maturity Level 2 — ASD Mitigation Strategies for Westlink Logistics
107 normative shall-statements extracted from Essential Eight Maturity Model — Maturity Level Two (source: ~/projects/DISP/e8_maturity_model.md). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.
Coverage summary
| Coverage | Count |
|---|---|
| ✅ Full | 12 |
| 🟡 Partial | 21 |
| 🟠 Ref-only | 0 |
| 🔴 Gap | 62 |
| — N/A | 12 |
Gap severity distribution
| Severity | Count |
|---|---|
| 🔴 Critical | 2 |
| 🟠 High | 48 |
| 🟡 Medium | 32 |
| 🟢 Low | 1 |
Requirements
Clause ML2-AC-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-01 | 🟡 Partial | [TEC-PRO-002 §‘System hardening / Responsibilities’](/wms/TEC-PRO-002#s’System hardening / Responsibilities’) | 🟠 High | Application control (AppLocker / Windows Defender Application Control / WDAC) not documented in WMS. 2024 Defence Cyber Assessment notes application control as ‘Embedded’ operationally but no WMS documentation exists. Becloudsmart-managed. |
Clause ML2-AC-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-02 | — N/A | — | N/A — |
Clause ML2-AC-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-03 | 🔴 Gap | — | 🟠 High | Not documented. Dependent on ISM-0843 being documented/verified. |
Clause ML2-AC-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-04 | 🔴 Gap | — | 🟠 High | Not documented. Dependent on ISM-0843 being documented/verified. |
Clause ML2-AC-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-05 | 🔴 Gap | — | 🟠 High | Approved-application set not documented. Required for both E8 ML2 and ISM — uplift needed. |
Clause ML2-AC-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-06 | 🔴 Gap | — | 🟠 High | Microsoft recommended blocklist implementation not documented. Operationally likely enforced via Defender / WDAC templates — needs confirming and documenting. |
Clause ML2-AC-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-07 | 🔴 Gap | — | 🟡 Medium | Annual ruleset validation not documented. No application-control ruleset documentation exists — prerequisite is implementing and documenting the ruleset. |
Clause ML2-AC-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-08 | 🔴 Gap | — | 🟡 Medium | Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
Clause ML2-AC-09
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-09 | 🔴 Gap | — | 🟠 High | Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
Clause ML2-AC-10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-10 | — N/A | — | N/A — |
Clause ML2-AC-11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-11 | 🔴 Gap | — | 🟠 High | Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
Clause ML2-AC-12
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-12 | ✅ Full | TEC-POL-001 [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-AC-13
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-13 | 🟡 Partial | [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
Clause ML2-AC-14
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-AC-14 | ✅ Full | [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-BAK-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-01 | 🟡 Partial | TEC-POL-001 | 🟠 High | Backup commitment stated in TEC-POL-001; retention-by-criticality schedule not documented. Microsoft native retention / third-party M365 backup (AvePoint, Veeam, etc.) arrangement not documented in WMS. BCP detail belongs in QHSE-PLN-002 (not yet issued per TEC-POL-001 changelog). |
Clause ML2-BAK-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-02 | 🔴 Gap | — | 🟠 High | Common point-in-time restoration not documented. Microsoft 365 native backup is not PIT — needs documented third-party solution or explicit acceptance of Microsoft retention defaults. |
Clause ML2-BAK-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-03 | 🟡 Partial | TEC-POL-001 | 🟡 Medium | Microsoft geo-redundancy provides resilience; backup-specific secure storage and tamper-resistance not separately addressed. Posture summary notes Microsoft mirrors data across regions — adequate for resilience, but backup-retention-specific security is not documented. |
Clause ML2-BAK-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-04 | 🔴 Gap | — | 🟠 High | ’Restoration testing from backup as part of DR exercises is NOT documented and likely NOT performed. Backup restore testing is explicitly flagged in the Westlink posture summary as needing documentation/configuration. Uplift: add to QHSE-PLN-002 BCP and establish annual DR test.‘ |
Clause ML2-BAK-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-05 | 🔴 Gap | — | 🟡 Medium | Unprivileged accounts prevented from accessing other accounts’ backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart). |
Clause ML2-BAK-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-06 | 🔴 Gap | — | 🟡 Medium | Backup-administrator role segregation not documented. Dependent on a dedicated backup solution / role being defined. |
Clause ML2-BAK-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-07 | 🔴 Gap | — | 🟡 Medium | Unprivileged accounts prevented from modifying/deleting backups — E8 ML2 backup control not documented in WMS; deferred to the 2027 ML2 uplift (Becloudsmart). |
Clause ML2-BAK-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-BAK-08 | 🔴 Gap | — | 🟡 Medium | Privileged-user backup modification restriction not documented. Needs dedicated backup admin role definition. |
Clause ML2-MAC-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MAC-01 | 🔴 Gap | — | 🟠 High | Office macro restriction not documented in WMS. No policy on Office macro management. Intune / Office admin centre can enforce this — needs documenting. |
Clause ML2-MAC-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MAC-02 | 🔴 Gap | — | 🟠 High | Internet-sourced macro block not documented. Microsoft’s default ‘block macros from the internet’ policy may be enforced operationally but needs documenting. |
Clause ML2-MAC-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MAC-03 | 🔴 Gap | — | 🟡 Medium | Macro antivirus scanning not documented. Defender integration likely covers this — needs documenting. |
Clause ML2-MAC-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MAC-04 | 🔴 Gap | — | 🟠 High | Win32 API call block for macros not documented. Requires Office ASR rule or equivalent configuration. |
Clause ML2-MAC-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MAC-05 | 🟡 Partial | [TEC-PRO-002 §‘System hardening’](/wms/TEC-PRO-002#s’System hardening’) | 🟠 High | User lockdown of macro security settings not documented. Group Policy / Intune Administrative Templates enforce this operationally — needs documenting. |
Clause ML2-MFA-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-01 | ✅ Full | TEC-POL-001 TEC-POL-002 |
Clause ML2-MFA-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-02 | 🟡 Partial | TEC-POL-002 [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) | 🟡 Medium | Third-party service MFA enforcement is implicit in the general cloud-services MFA commitment but not separately addressed. Spot-check per-service MFA status (JOSCAR portal, Hellios, etc.) and document exceptions. |
Clause ML2-MFA-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-03 | 🟡 Partial | TEC-POL-002 | 🟢 Low | Non-sensitive third-party service MFA not separately called out. Low risk given data sensitivity. |
Clause ML2-MFA-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-04 | — N/A | — | N/A — |
Clause ML2-MFA-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-05 | — N/A | — | N/A — |
Clause ML2-MFA-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-06 | — N/A | — | N/A — |
Clause ML2-MFA-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-07 | ✅ Full | TEC-POL-001 TEC-POL-002 [TEC-PRO-002 §‘System administration / System hardening’](/wms/TEC-PRO-002#s’System administration / System hardening’) |
Clause ML2-MFA-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-08 | ✅ Full | TEC-POL-002 [TEC-PRO-002 §‘System hardening’](/wms/TEC-PRO-002#s’System hardening’) |
Clause ML2-MFA-09
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-09 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | Factor-type requirement (have+know or have+know/are) not documented in WMS. Microsoft Authenticator (something you have) + passcode (know) or biometric (are) meets control operationally; needs documenting. |
Clause ML2-MFA-10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-10 | 🔴 Gap | — | 🔴 Critical | Phishing-resistant MFA (FIDO2, Windows Hello for Business, certificate-based) is NOT currently deployed per Westlink posture summary (Feb 2025) — current MFA is Authenticator push/code which is not phishing-resistant. This will be a likely DISP ASR audit finding within 12 months. Uplift plan required. |
Clause ML2-MFA-11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-11 | — N/A | — | N/A — |
Clause ML2-MFA-12
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-12 | 🔴 Gap | — | 🔴 Critical | Phishing-resistant MFA not deployed. Same gap as ISM-1872 — FIDO2 / Windows Hello for Business uplift required for DISP ASR. |
Clause ML2-MFA-13
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-13 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | Access log commitment exists in TEC-POL-002 but central MFA-event logging not explicitly called out. Entra sign-in logs provide this operationally. |
Clause ML2-MFA-14
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-14 | 🔴 Gap | — | 🟠 High | Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
Clause ML2-MFA-15
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-15 | — N/A | — | N/A — |
Clause ML2-MFA-16
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-16 | 🔴 Gap | — | 🟠 High | Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
Clause ML2-MFA-17
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-17 | ✅ Full | TEC-POL-001 [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-MFA-18
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-18 | 🟡 Partial | [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
Clause ML2-MFA-19
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-19 | ✅ Full | [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-PA-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-01 | 🔴 Gap | — | 🟠 High | Asset discovery cadence not documented in WMS. Likely covered operationally via Intune device inventory but no controlled documentation. Technical evidence is external (Intune/Entra). |
Clause ML2-PA-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-02 | 🔴 Gap | — | 🟠 High | Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
Clause ML2-PA-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-03 | 🔴 Gap | — | 🟠 High | Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
Clause ML2-PA-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-04 | 🔴 Gap | — | 🟠 High | Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
Clause ML2-PA-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-05 | 🔴 Gap | — | 🟠 High | Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
Clause ML2-PA-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-06 | ✅ Full | TEC-POL-001 |
Clause ML2-PA-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-07 | 🟡 Partial | TEC-POL-001 | 🟠 High | Two-week cadence for non-critical online-service vulnerabilities not documented at control level — need implementing procedure. |
Clause ML2-PA-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-08 | 🔴 Gap | — | 🟠 High | Application-side patching cadence (Office, browsers, email clients, PDF, security) not documented in WMS. Operationally likely handled via Intune Windows Update for Business and Edge/Chrome auto-update, but not captured in a controlled document. |
Clause ML2-PA-09
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-09 | 🔴 Gap | — | 🟡 Medium | Patching cadence for general applications not documented. Westlink cloud-only M365 estate — small 3rd-party app footprint but still in scope. Needs procedure. |
Clause ML2-PA-10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-10 | 🔴 Gap | — | 🟡 Medium | No documented process for removing unsupported online services. Operationally likely managed via Entra app governance / Becloudsmart, but not documented in WMS. |
Clause ML2-PA-11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-PA-11 | 🔴 Gap | — | 🟡 Medium | No documented process for removing unsupported applications. Likely handled operationally via Intune application management. |
Clause ML2-POS-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-01 | 🔴 Gap | — | 🟠 High | Asset discovery for OS scope not documented in WMS. Likely handled via Intune device inventory — not captured in controlled documentation. |
Clause ML2-POS-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-02 | 🔴 Gap | — | 🟠 High | Patching cadence is not specified in any WMS document at the control level required by E8 ML2. Technical evidence lives in Intune/Defender vulnerability management tooling (cloud-only M365 estate); needs documented in a Cyber Security Procedure (TEC-PRO-001 planned but not yet created). |
Clause ML2-POS-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-03 | — N/A | — | N/A — |
Clause ML2-POS-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-04 | 🔴 Gap | — | 🟠 High | Workstation OS vulnerability scanning cadence not documented in WMS. Intune + Defender for Endpoint provide this operationally but not documented in a controlled procedure. |
Clause ML2-POS-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-05 | — N/A | — | N/A — |
Clause ML2-POS-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-06 | — N/A | — | N/A — |
Clause ML2-POS-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-07 | 🟡 Partial | TEC-POL-001 | 🟠 High | Workstation patching one-month cadence not documented at control level. Intune Windows Update for Business provides this operationally — needs documenting in TEC-PRO-001. |
Clause ML2-POS-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-POS-08 | 🔴 Gap | — | 🟡 Medium | No documented lifecycle for unsupported operating systems. Likely covered operationally by Intune hardware refresh cycle — not documented in WMS. |
Clause ML2-RAP-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-01 | 🟡 Partial | TEC-POL-002 [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) | 🟡 Medium | Generic approval requirement is present; specific validation workflow for privileged access (separate approval chain, business-justification artefact, periodic attestation) not documented. Needs procedural uplift. |
Clause ML2-RAP-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-02 | 🟡 Partial | TEC-POL-002 [TEC-POL-001 §Policy Commitments](/wms/TEC-POL-001#sPolicy Commitments) | 🟡 Medium | 12-month review cadence documented; explicit ‘disable unless revalidated’ enforcement mechanism not spelled out. Operationally covered via Entra access reviews. |
Clause ML2-RAP-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-03 | 🔴 Gap | — | 🟠 High | 45-day inactivity disable is not documented in any WMS policy. Entra ID policies likely enforce this operationally but need documenting. |
Clause ML2-RAP-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-04 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | ’Named individuals’ and ‘no generic accounts’ implies dedicated privileged accounts but the two-account model (separate unprivileged daily-use + privileged admin) is not explicitly stated. |
Clause ML2-RAP-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-05 | 🟡 Partial | [TEC-PRO-002 §‘System administration’](/wms/TEC-PRO-002#s’System administration’) | 🟠 High | Privileged account internet/email restriction not documented. For cloud-only M365, this is enforced via Conditional Access policies scoped to privileged roles — needs documenting as a control. |
Clause ML2-RAP-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-06 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | Least-privilege principle is stated; specific scoping for privileged-user online-service access is not separately addressed. |
Clause ML2-RAP-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-07 | 🔴 Gap | — | 🟠 High | Separate privileged/unprivileged operating environments (Privileged Access Workstation or similar) not documented. Cloud-only M365 estate — implementation via Microsoft Secure Admin Workstation or Cloud PC is the likely uplift path. Not in place per posture summary. |
Clause ML2-RAP-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-08 | 🔴 Gap | — | 🟠 High | No documented policy. Dependent on separate privileged OE being implemented first. |
Clause ML2-RAP-09
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-09 | 🔴 Gap | — | 🟠 High | Not documented. Dependent on separate privileged OE being implemented first. |
Clause ML2-RAP-10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-10 | 🔴 Gap | — | 🟠 High | Not documented. Dependent on two-account model being implemented first. |
Clause ML2-RAP-11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-11 | 🔴 Gap | — | 🟡 Medium | Jump server use not documented. For cloud-only M365 the equivalent control is Microsoft Entra Privileged Identity Management / Azure Bastion for privileged sessions — needs documenting if adopted, or formal risk acceptance if not applicable to the cloud-only model. |
Clause ML2-RAP-12
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-12 | 🔴 Gap | — | 🟠 High | Break-glass / local admin / service account credential standards not documented. Emergency access account management is a DISP ASR focus — needs explicit control in TEC-POL-002 or a dedicated Privileged Access Standard. |
Clause ML2-RAP-13
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-13 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | Enhanced logging commitment exists; central log retention beyond Entra audit logs is not explicitly addressed (Defender for Cloud Apps / Sentinel integration not documented). |
Clause ML2-RAP-14
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-14 | 🟡 Partial | TEC-POL-002 | 🟡 Medium | Group-management event logging covered implicitly. Entra audit logs cover this operationally. |
Clause ML2-RAP-15
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-15 | 🔴 Gap | — | 🟠 High | Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
Clause ML2-RAP-16
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-16 | — N/A | — | N/A — |
Clause ML2-RAP-17
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-17 | 🔴 Gap | — | 🟠 High | Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
Clause ML2-RAP-18
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-18 | ✅ Full | TEC-POL-001 [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-RAP-19
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-19 | 🟡 Partial | [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
Clause ML2-RAP-20
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-RAP-20 | ✅ Full | [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Clause ML2-UAH-01
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-01 | 🔴 Gap | — | 🟡 Medium | IE11 removal not documented. Windows 11 has IE11 disabled by default — needs documenting as a baseline control. |
Clause ML2-UAH-02
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-02 | 🔴 Gap | — | 🟡 Medium | Java browser plugin block not documented. Modern browsers (Edge, Chrome) do not support Java plugins by default — needs documenting as a baseline control. |
Clause ML2-UAH-03
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-03 | 🔴 Gap | — | 🟡 Medium | Ad-blocking not documented. No enterprise ad-blocker deployment currently. Needs policy decision and deployment. |
Clause ML2-UAH-04
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-04 | 🔴 Gap | — | 🟠 High | Browser hardening baseline not documented. Needs ASD Edge/Chrome hardening guide applied via Intune Administrative Templates. |
Clause ML2-UAH-05
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-05 | 🔴 Gap | — | 🟡 Medium | User lockdown of browser security settings not documented. Intune Administrative Templates enforce this operationally. |
Clause ML2-UAH-06
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-06 | 🔴 Gap | — | 🟠 High | ASR rule for Office child-process blocking not documented. Attack Surface Reduction rule implementation needed via Intune. |
Clause ML2-UAH-07
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-07 | 🔴 Gap | — | 🟠 High | ASR rule for Office executable-content blocking not documented. |
Clause ML2-UAH-08
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-08 | 🔴 Gap | — | 🟠 High | ASR rule for Office code-injection blocking not documented. |
Clause ML2-UAH-09
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-09 | 🔴 Gap | — | 🟠 High | OLE package activation block not documented. |
Clause ML2-UAH-10
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-10 | 🔴 Gap | — | 🟠 High | Office hardening baseline not documented. ASD M365 hardening guidance not applied in a controlled WMS document. |
Clause ML2-UAH-11
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-11 | 🔴 Gap | — | 🟡 Medium | User lockdown of Office security settings not documented. Intune Administrative Templates enforce this operationally. |
Clause ML2-UAH-12
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-12 | 🔴 Gap | — | 🟡 Medium | ASR rule for PDF software not documented. If Adobe Acrobat Reader is used, hardening baseline needed; Edge PDF viewer may be the primary PDF tool in Westlink’s estate. |
Clause ML2-UAH-13
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-13 | 🔴 Gap | — | 🟡 Medium | PDF hardening baseline not documented. |
Clause ML2-UAH-14
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-14 | 🔴 Gap | — | 🟡 Medium | User lockdown of PDF software settings not documented. |
Clause ML2-UAH-15
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-15 | 🔴 Gap | — | 🟡 Medium | PowerShell logging not documented. Intune / Defender for Endpoint / Sentinel integration likely handles this — needs documenting. |
Clause ML2-UAH-16
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-16 | 🔴 Gap | — | 🟡 Medium | Command-line process creation logging not documented. Defender for Endpoint captures this operationally. |
Clause ML2-UAH-17
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-17 | 🔴 Gap | — | 🟠 High | Central logging and protected-log-retention requirements are not addressed in any WMS document. Westlink is cloud-only M365 — Defender/Sentinel capability likely exists via Becloudsmart but is not documented in the controlled WMS corpus. |
Clause ML2-UAH-18
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-18 | — N/A | — | N/A — |
Clause ML2-UAH-19
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-19 | 🔴 Gap | — | 🟠 High | Timely analysis of cybersecurity events from internet-facing servers is not documented in the WMS. Becloudsmart-managed capability per 2024 Defence Cyber Assessment — not captured in a controlled WMS procedure. |
Clause ML2-UAH-20
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-20 | ✅ Full | TEC-POL-001 [TEC-PRO-001 §‘Detection and Reporting’](/wms/TEC-PRO-001#s’Detection and Reporting’) |
Clause ML2-UAH-21
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-21 | 🟡 Partial | [TEC-PRO-001 §‘External Notification Pathways’](/wms/TEC-PRO-001#s’External Notification Pathways’) | 🟠 High | TEC-PRO-001 §External Notification documents the ASD reporting pathway via ReportCyber, lodged by the Security Officer. Residual — reporting timeliness and discipline not yet operationally evidenced; confirm at next DISP ASR. Re-rated Gap->Partial S160 per F70. |
Clause ML2-UAH-22
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| E8-ML2-UAH-22 | ✅ Full | [TEC-PRO-001 §‘Response Lifecycle’](/wms/TEC-PRO-001#s’Response Lifecycle’) |
Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.