Summary of key changes since previous version The title and scope of the publication have been updated to mitigate additional threats. Three new mitigation strategies to recover data and system availability help mitigate ransomware. The new mitigation strategies ‘Personnel management’ and ‘Outbound web and email data loss prevention’ help mitigate malicious insiders. The Mitigation Details publication has new guidance for these threats as well as for business email compromise and industrial control systems. The leftmost numerical ranking column was being misinterpreted by some readers, and has been converted into a suggested mitigation strategy implementation order for each threat, providing a principles-based approach to building a defence-in-depth cyber security posture. The rightmost four columns (e.g. ‘Helps Prevent Intrusion Stage 1: Code Execution’) have been converted into category headings (e.g. ‘Mitigation Strategies to Prevent Malware Delivery and Execution’). Mitigation strategies have been categorised based on their primary security outcome. Effectiveness ratings now include ‘very good’, while ‘average’ has been changed to ‘limited’. Mitigation strategy ‘Application control’ now mentions Windows Script Host, PowerShell and HTML Applications (HTA). Further guidance has been added to the Mitigation Details publication. The two patching mitigation strategies now reference the ACSC’s definition of ‘extreme risk’ security vulnerabilities to reflect that the 48 hour (previously two day) timeframe to apply patches doesn’t apply to every security vulnerability affecting every computer. The list of applications has been reordered since Flash, web browsers and Microsoft Office are exploited more than Java and PDF viewers. New mitigation strategy ‘Configure Microsoft Office macro settings’ has been extracted from mitigation strategy ‘User application hardening’ to reflect the prevalence of malicious Microsoft Office macros. The ACSC has seen our guidance mitigate attempts to compromise Australian organisations by adversaries working for a foreign intelligence service. Mitigation strategy ‘User application hardening’ is now rated ‘essential’ and advises to uninstall Adobe Flash if possible, disable Microsoft Office OLE packages, and block internet ads due to malicious advertising (malvertising). Some organisations might choose to support selected websites that rely on ads for revenue by enabling just their ads and potentially risking compromise. Mitigation strategy ‘Multi-factor authentication’ is now rated ‘essential’ to reflect the prevalence of passphrase theft and the abuse of remote access for infiltration, data exfiltration and persistence. Mitigation strategy ‘Enforce a strong passphrase policy’ has been renamed to ‘Protect authentication credentials’, contains specific new guidance and is now rated ‘excellent’. The two logging mitigation strategies have been combined into mitigation strategy ‘Continuous incident detection and response’. Also, while the key goal remains to identify and protect assets to prevent cyber security incidents, two new mitigation strategies reduce the time to detect and respond to such incidents – ‘Endpoint detection and response software’ and ‘Hunt to discover incidents’ leveraging threat intelligence. Details are in the Mitigation Details publication. Mitigation strategy ‘Server application hardening’ is now rated ‘very good’ to reflect an increase in cyber security incidents involving web servers compromised with web shells. Mitigation strategy ‘Block spoofed emails’ now advises to configure DMARC DNS records. Mitigation strategies ‘Web domain whitelisting for all domains’, ‘Block attempts to access websites by their IP address’ and ‘Gateway blacklisting’ have merged into ‘Web content filtering’. Mitigation strategies ‘Restrict access to Server Message Block (SMB) and NetBIOS’ and ‘Workstation inspection of Microsoft Office files’ have merged with existing mitigation strategies. Contact details If you have any questions regarding this guidance you can write to us or call us on 1300 CYBER1 (1300 292 371). 3

Select target paragraph3