Skip to content

Essential EightPCI DSS crosswalk

A control-by-control mapping between ACSC Essential Eight and PCI DSS v4.0. 9 mappings.

Essential EightPCI DSSRelationshipNotes
E8-1
Patch applications
Req. 11
Test security of systems and networks regularly
EquivalentCurated
Gestion des vulnérabilités
E8-2
Patch operating systems
Req. 11
Test security of systems and networks regularly
EquivalentCurated
Gestion des vulnérabilités
E8-3
Multi-factor authentication
Req. 7
Restrict access by business need to know
PartialCurated
Contrôle d'accès et identité
E8-3
Multi-factor authentication
Req. 8
Identify users and authenticate access
PartialCurated
Contrôle d'accès et identité
E8-4
Restrict administrative privileges
Req. 7
Restrict access by business need to know
PartialCurated
Contrôle d'accès et identité
E8-4
Restrict administrative privileges
Req. 8
Identify users and authenticate access
PartialCurated
Contrôle d'accès et identité
E8-5
Application control
Req. 2
Apply secure configurations to all system components
PartialCurated
Configuration sécurisée et durcissement
E8-6
Restrict Microsoft Office macros
Req. 2
Apply secure configurations to all system components
PartialCurated
Configuration sécurisée et durcissement
E8-7
User application hardening
Req. 2
Apply secure configurations to all system components
PartialCurated
Configuration sécurisée et durcissement

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.