Summary of key changes since previous version
The title and scope of the publication have been updated to mitigate additional threats. Three new mitigation strategies
to recover data and system availability help mitigate ransomware. The new mitigation strategies ‘Personnel
management’ and ‘Outbound web and email data loss prevention’ help mitigate malicious insiders. The Mitigation
Details publication has new guidance for these threats as well as for business email compromise and industrial control
systems.
The leftmost numerical ranking column was being misinterpreted by some readers, and has been converted into a
suggested mitigation strategy implementation order for each threat, providing a principles-based approach to building
a defence-in-depth cyber security posture.
The rightmost four columns (e.g. ‘Helps Prevent Intrusion Stage 1: Code Execution’) have been converted into category
headings (e.g. ‘Mitigation Strategies to Prevent Malware Delivery and Execution’). Mitigation strategies have been
categorised based on their primary security outcome.
Effectiveness ratings now include ‘very good’, while ‘average’ has been changed to ‘limited’.
Mitigation strategy ‘Application control’ now mentions Windows Script Host, PowerShell and HTML Applications (HTA).
Further guidance has been added to the Mitigation Details publication.
The two patching mitigation strategies now reference the ACSC’s definition of ‘extreme risk’ security vulnerabilities to
reflect that the 48 hour (previously two day) timeframe to apply patches doesn’t apply to every security vulnerability
affecting every computer. The list of applications has been reordered since Flash, web browsers and Microsoft Office
are exploited more than Java and PDF viewers.
New mitigation strategy ‘Configure Microsoft Office macro settings’ has been extracted from mitigation strategy ‘User
application hardening’ to reflect the prevalence of malicious Microsoft Office macros. The ACSC has seen our guidance
mitigate attempts to compromise Australian organisations by adversaries working for a foreign intelligence service.
Mitigation strategy ‘User application hardening’ is now rated ‘essential’ and advises to uninstall Adobe Flash if possible,
disable Microsoft Office OLE packages, and block internet ads due to malicious advertising (malvertising). Some
organisations might choose to support selected websites that rely on ads for revenue by enabling just their ads and
potentially risking compromise.
Mitigation strategy ‘Multi-factor authentication’ is now rated ‘essential’ to reflect the prevalence of passphrase theft
and the abuse of remote access for infiltration, data exfiltration and persistence.
Mitigation strategy ‘Enforce a strong passphrase policy’ has been renamed to ‘Protect authentication credentials’,
contains specific new guidance and is now rated ‘excellent’.
The two logging mitigation strategies have been combined into mitigation strategy ‘Continuous incident detection and
response’. Also, while the key goal remains to identify and protect assets to prevent cyber security incidents, two new
mitigation strategies reduce the time to detect and respond to such incidents – ‘Endpoint detection and response
software’ and ‘Hunt to discover incidents’ leveraging threat intelligence. Details are in the Mitigation Details
publication.
Mitigation strategy ‘Server application hardening’ is now rated ‘very good’ to reflect an increase in cyber security
incidents involving web servers compromised with web shells.
Mitigation strategy ‘Block spoofed emails’ now advises to configure DMARC DNS records.
Mitigation strategies ‘Web domain whitelisting for all domains’, ‘Block attempts to access websites by their IP address’
and ‘Gateway blacklisting’ have merged into ‘Web content filtering’.
Mitigation strategies ‘Restrict access to Server Message Block (SMB) and NetBIOS’ and ‘Workstation inspection of
Microsoft Office files’ have merged with existing mitigation strategies.
Contact details
If you have any questions regarding this guidance you can write to us or call us on 1300 CYBER1 (1300 292 371).
3