This directory contains comprehensive security checklists for implementing the Essential Eight Maturity Model across various hosting platforms. Each checklist is tailored to the specific features and services of its respective platform while maintaining alignment with the Essential Eight framework.
Complete security checklist for organizations managing their own physical infrastructure, including:
- Physical security controls
- Network infrastructure
- Server room/data center requirements
- Disaster recovery planning
- Hardware lifecycle management
Comprehensive guide for securing Amazon Web Services infrastructure:
- AWS-specific service configurations
- IAM and access management
- VPC and network security
- Compliance frameworks (CIS, Well-Architected)
- Cost optimization with security
Detailed checklist for Microsoft Azure deployments:
- Azure AD and identity management
- Microsoft Defender for Cloud
- Network security with NSGs and Azure Firewall
- Compliance with Azure Security Benchmark
- Integration with Microsoft 365 security
Security implementation guide for GCP:
- Cloud Identity and IAM
- VPC Service Controls
- Security Command Center
- BeyondCorp and Zero Trust
- Compliance with Google Cloud security best practices
Choose the checklist that matches your hosting environment. If you use multiple platforms, review each relevant checklist.
Go through each item and mark your current compliance level:
- ✅ Implemented
- 🔄 In Progress
- ❌ Not Started
- N/A Not Applicable
Each checklist includes implementation phases:
- Phase 1: Critical security controls (Immediate)
- Phase 2: High priority items (30 days)
- Phase 3: Medium priority items (90 days)
- Phase 4: Ongoing improvements
All checklists are organized by Essential Eight Maturity Levels:
- ML1: Basic cyber hygiene
- ML2: Enhanced security posture
- ML3: Advanced protection against sophisticated threats
| Feature | On-Premise | AWS | Azure | GCP |
|---|---|---|---|---|
| Physical Security | Full Control | AWS Managed | Microsoft Managed | Google Managed |
| Network Control | Complete | VPC-based | VNet-based | VPC-based |
| Identity Provider | AD/LDAP | IAM/SSO | Azure AD | Cloud Identity |
| Patch Management | Manual/SCCM | Systems Manager | Update Management | OS Config |
| Backup Solution | Third-party | AWS Backup | Azure Backup | Cloud Storage |
| Compliance Tools | Third-party | Security Hub | Defender for Cloud | Security Command Center |
| Cost Model | CapEx | OpEx | OpEx | OpEx |
| Shared Responsibility | Full | Shared | Shared | Shared |
- Application Control - Whitelisting and execution control
- Patch Applications - Regular security updates
- Configure Office Macros - Restrict macro execution
- User Application Hardening - Browser and application security
- Restrict Admin Privileges - Least privilege access
- Patch Operating Systems - OS security updates
- Multi-factor Authentication - Strong authentication
- Regular Backups - Data protection and recovery
- Network segmentation
- Encryption at rest and in transit
- Security monitoring and SIEM
- Incident response planning
- Compliance management
- Vulnerability management
- Security awareness training
If you're using multiple platforms:
-
Consistent Security Policies
- Standardize security controls across platforms
- Use cloud-agnostic tools where possible
- Maintain unified compliance reporting
-
Centralized Management
- Consider CSPM (Cloud Security Posture Management) tools
- Implement unified SIEM/SOAR
- Centralize identity management
-
Network Connectivity
- Secure interconnections between platforms
- Consistent network security policies
- Unified threat detection
Each checklist includes automation examples:
- On-Premise: PowerShell, Ansible, Puppet
- AWS: CloudFormation, Terraform, AWS CLI
- Azure: ARM Templates, Terraform, Azure CLI
- GCP: Deployment Manager, Terraform, gcloud
All checklists align with:
- Australian Government Information Security Manual (ISM)
- NIST Cybersecurity Framework
- CIS Controls
- ISO 27001/27002
- Industry-specific requirements (PCI DSS, HIPAA, etc.)
Security is an ongoing process:
- Review checklists quarterly
- Update based on new threats
- Incorporate platform updates
- Adjust for compliance changes
- Learn from security incidents
We welcome contributions to improve these checklists:
- Report issues or gaps
- Submit pull requests with improvements
- Share implementation experiences
- Suggest new platform checklists
For questions or assistance:
- Open an issue in the repository
- Consult platform-specific support channels
- Engage with the security community
- Consider professional security consulting
Remember: Security is a journey, not a destination. These checklists provide a framework, but must be adapted to your specific needs, risk profile, and compliance requirements.