Australia

ASD Strategies to Mitigate Cyber Security Incidents

37 controls. 290 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

37 controls 290 frameworks share controls with it Australia verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ASD Strategies to Mitigate Cyber Security Incidents Evidence & Implementation Kit

37 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ASD37-01Application control (Essential)24
ASD37-02Patch applications (Essential)23
ASD37-03Configure Microsoft Office macro settings (Essential)18
ASD37-04User application hardening (Essential)75
ASD37-05Automated dynamic analysis of email and web content (Excellent)20
ASD37-06Email content filtering (Excellent)55
ASD37-07Web content filtering (Excellent)22
ASD37-08Deny direct internet connectivity (Excellent)20
ASD37-09OS generic exploit mitigation (Excellent)16
ASD37-10Server application hardening (Very Good)74
ASD37-11Operating system hardening (Very Good)75
ASD37-12Antivirus software with heuristics (Very Good)69
ASD37-13Control removable storage media (Very Good)24
ASD37-14Block spoofed emails (Very Good)14
ASD37-15User education (Limited)23
ASD37-16Antivirus software with signatures (Limited)68
ASD37-17TLS encryption between email servers (Limited)155
ASD37-18Restrict administrative privileges (Essential)103
ASD37-19Patch operating systems (Essential)23
ASD37-20Multi-factor authentication (Essential)178
ASD37-21Disable local administrator accounts (Excellent)23
ASD37-22Network segmentation (Excellent)87
ASD37-23Protect authentication credentials (Excellent)107
ASD37-24Non-persistent virtualised sandboxed environment (Very Good)10
ASD37-25Software firewall - inbound (Very Good)84
ASD37-26Software firewall - outbound (Very Good)17
ASD37-27Outbound data loss prevention (Very Good)127
ASD37-28Continuous incident detection and response (Excellent)25
ASD37-29Host-based IDS/IPS (Very Good)61
ASD37-30Endpoint detection and response (Very Good)20
ASD37-31Hunt to discover incidents (Very Good)159
ASD37-32Network-based IDS/IPS (Limited)60
ASD37-33Capture network traffic (Limited)157
ASD37-34Regular backups (Essential)103
ASD37-35Business continuity and disaster recovery plans (Very Good)108
ASD37-36System recovery capabilities (Very Good)102
ASD37-37Personnel management (Very Good)51

Tell me when ASD Strategies to Mitigate Cyber Security Incidents files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ASD Strategies to Mitigate Cyber Security Incidents, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition