Skip to content

Essential EightISO 27001 crosswalk

A control-by-control mapping between ACSC Essential Eight and ISO/IEC 27001:2022. 10 mappings.

Essential EightISO 27001RelationshipNotes
E8-1
Patch applications
A.8.8
Management of technical vulnerabilities
EquivalentCurated
Vulnerability management
E8-2
Patch operating systems
A.8.8
Management of technical vulnerabilities
EquivalentCurated
Vulnerability management
E8-3
Multi-factor authentication
A.5.15
Access control
PartialCurated
Access control & identity
E8-3
Multi-factor authentication
A.5.16
Identity management
PartialCurated
Access control & identity
E8-4
Restrict administrative privileges
A.5.15
Access control
PartialCurated
Access control & identity
E8-4
Restrict administrative privileges
A.5.16
Identity management
PartialCurated
Access control & identity
E8-5
Application control
A.8.9
Configuration management
PartialCurated
Secure configuration & hardening
E8-6
Restrict Microsoft Office macros
A.8.9
Configuration management
PartialCurated
Secure configuration & hardening
E8-7
User application hardening
A.8.9
Configuration management
PartialCurated
Secure configuration & hardening
E8-8
Regular backups
A.8.13
Information backup
EquivalentCurated
Backup & recovery

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.