Cyberdaily.Au ASD to Retire Essential Eight Cyber Security Framework in Two Years
Article Content
- •ASD plans to retire the Essential Eight framework within two years.
- •The new 'Essentials' series will focus on outcomes and flexibility in security measures.
- •Initial chapters will address enterprise IT, operational technology, and cloud security.
The Australian Signals Directorate (ASD) announced plans to retire the Essential Eight framework within two years, replacing it with a new 'Essentials' series. This change aims to address the evolving cyber security landscape, particularly with the rise of cloud computing and operational technology. Chris Horlyck from the ASD stated that the Essential Eight would remain active during the transition, with a phased retirement expected over 24 months. The new framework will focus on outcomes rather than prescriptive controls, allowing organizations greater flexibility in their security measures. Initial chapters will cover enterprise IT, operational technology, and cloud, with potential inclusion of agentic AI. The shift is partly in response to criticisms that the Essential Eight's maturity level requirements have become misaligned with current security practices. The transition aims to provide clearer guidance on shared responsibilities in cloud environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…