Compliance

Essential Eight

Which of the ACSC Essential Eight mitigation strategies Besecure contributes evidence to, and which it does not touch.

Where Besecure helps

Two of the eight, described honestly

The Essential Eight is the Australian Signals Directorate's set of eight mitigation strategies, assessed across four maturity levels. An identity and access product can speak to two of them. Anyone telling you their access tool covers all eight is selling you something other than accuracy.

Multi-factor authentication

Besecure puts a second factor in front of the applications you publish through it, and lets you require enrolment rather than invite it.

  • Two-factor authentication by authenticator app or one-time code
  • Enrolment enforced, so setup happens before someone reaches an application
  • The same authentication policy applies to administrators
  • Password policy, complexity, rotation and automatic lockout set per organisation
  • Every sign-in and failed attempt recorded in the audit log

What this does not cover. Besecure's second factors are an authenticator app and one-time codes. The ACSC expects phishing-resistant methods — passkeys or hardware security keys — at the higher maturity levels, and Besecure does not currently offer those. If your assessment requires phishing-resistant MFA, say so early and we will tell you plainly whether we can meet it.

Restrict administrative privileges

Administrative access in Besecure is granular, reviewable and — where it is only needed for a task — temporary.

  • Granular administrator role permissions rather than one admin tier
  • Time-boxed support access, so elevated help expires instead of standing
  • Shared identities for the accounts that genuinely cannot be individual
  • Departments, groups and roles so access is granted by position, not by request
  • Administrative changes captured in the audit log, exportable for review

What this does not cover. This covers privileged access to the applications Besecure publishes and to Besecure itself. It does not touch local administrator rights on laptops and servers, or privileged accounts inside systems you have not published through Besecure — both of which a full assessment of this strategy will look at.

Where Besecure does not help

The other six strategies

These sit outside an access layer. We list them because a vendor who shows you the boundary is easier to check than one who leaves you to find it.

Patch applications

Outside what Besecure does.

Patch operating systems

Outside what Besecure does.

Application control

Outside what Besecure does.

Restrict Microsoft Office macros

Outside what Besecure does.

User application hardening

Outside what Besecure does.

Regular backups

Outside what Besecure does.

Questions

What buyers ask us about this

Does running Besecure make us Essential Eight compliant?

No. The Essential Eight is assessed against your organisation and the whole of your environment, not against any single product. Besecure contributes evidence to two of the eight mitigation strategies. The other six are outside what an access layer can do.

Which maturity level does Besecure meet?

A product does not hold a maturity level — your organisation is assessed at one. We deliberately do not put a number on this page, because the honest answer depends on your environment and on which factors your assessor accepts. What we can tell you precisely is which controls exist in the product, which is what the two sections above set out.

Is your MFA phishing-resistant?

Not in the sense the ACSC uses at the higher maturity levels. Besecure supports an authenticator app and one-time codes, not passkeys or hardware security keys. If phishing-resistant MFA is a requirement for your assessment, raise it with us at the start rather than at the end.

Can you give us evidence for an audit?

Yes. Sign-ins, failed attempts and administrative changes are held in one audit log with configurable retention, and reports export to Excel or Word.

Do you hold an IRAP assessment or a certification?

We publish nothing on this site that we cannot evidence. Ask us directly and you will get the current position in writing rather than a badge on a marketing page.

Bring us your assessment questions

Tell us which strategies and maturity level you are being held to, and we will tell you what Besecure covers and what you will need to solve elsewhere.