The Essential Eight, and the part of it we can honestly evidence.
The ACSC’s Essential Eight is eight mitigation strategies. SecureFlow can produce real evidence for two of them, part of three more, and none at all for the last three. That is the true answer, it is on this page rather than in a footnote, and it is the same table the product shows you.
A vendor who tells you they cover the Essential Eight is telling you they cover application control, which is enforced on endpoints, by a product that reads source code. They cannot. Knowing which three you still have to evidence yourself is worth more than a claim you will have to walk back in an assessment.
The eight, and where we stand on each
Patch applications
We evidence thisWhat we see. Every dependency in the repositories and images you have connected, the vulnerabilities known against them, and how long each has been outstanding.
What we do not. Applications installed on laptops and servers that are not in a repository we can read — browsers, office software, anything installed by hand.
Covering the rest. For the rest, your endpoint management tool is the source. This covers the software you build and ship.
Patch operating systems
PartlyWhat we see. Base images in your containers and the operating system packages inside them, with the vulnerabilities known against those versions.
What we do not. The operating systems on physical machines, virtual machines you do not build from an image we scan, and anything managed outside the accounts you have connected.
Covering the rest. Connect the cloud accounts those machines run in, and this covers more of it. Machines outside them need your own patch management records.
Multi-factor authentication
PartlyWhat we see. Whether multi-factor authentication is enforced on SecureFlow itself, and misconfigurations we find in the identity settings of cloud accounts you have connected.
What we do not. Your email, your VPN, your line-of-business systems, and every other place your people sign in. Which is most of what this control is about.
Covering the rest. Your identity provider holds this evidence. We can carry its export into a report, but we cannot produce it.
Restrict administrative privileges
PartlyWhat we see. Over-broad permissions in the cloud accounts and repositories you have connected — a role with more than it needs, a token that can write where it should only read.
What we do not. Administrative accounts on workstations and servers, domain administrators, and privileged access to systems you have not connected.
Covering the rest. Your directory and privileged access management records cover the rest.
Application control
Not at allWhat we see. Nothing. This control is about which executables are allowed to run on your machines.
What we do not. All of it. Application control is enforced on endpoints, and scanning source code sees none of it.
Covering the rest. Your endpoint protection or application allow-listing tool holds this evidence. We do not, and a report from us should not imply otherwise.
Restrict Microsoft Office macros
Not at allWhat we see. Nothing. This control is about Office settings on your users’ machines.
What we do not. All of it: whether macros are blocked, whether they are allowed only from trusted locations, and whether users can turn that off. None of it is visible from source code.
Covering the rest. Your group policy or endpoint management configuration is the evidence for this, and an assessor will ask to see the policy rather than a report.
User application hardening
Not at allWhat we see. Nothing directly. Some of what we find — an outdated browser in a container image, a risky runtime setting in your infrastructure — touches the same ground, but it is not this control.
What we do not. Browser and Office hardening on user machines, which is what this control means.
Covering the rest. Your endpoint configuration baseline is the evidence for this.
Regular backups
Not at allWhat we see. Nothing. We do sometimes find backup *configuration* problems in infrastructure code — a bucket with no versioning, a database with no retention — and those are reported as findings rather than as evidence for this control.
What we do not. Whether backups are taken, whether they are tested, and whether they can be restored. Which is the whole control.
Covering the rest. Your backup tooling and, more importantly, your restoration test records. An untested backup is the thing this control exists to prevent.
Maturity levels
Maturity levels are assessed against your whole environment, not against one tool. We produce the evidence for the parts we see, dated and signed, in the form an assessor asks for — and we name the parts we do not.
What you actually get
A readiness report, dated and signed, that an assessor can work from — plus the Proof of Fix records behind each remediation it claims.