CYBER BASELINE · 8 MIN READ

Essential Eight ML2 checklist for DISP membership applicants

If you are aiming for DISP membership and your blocker is the cyber domain, you need more than a strategy slide. You need an Essential Eight ML2 evidence pack. This checklist is the conversation we have with applicants before they tell a prime "we're nearly there."

How to use this Essential Eight ML2 checklist

Work strategy by strategy. For each item, capture: current state, gap, owner, target date, and the artefact you will show an assessor. "In progress" without artefacts is not readiness.

1. Application control

  • Do you prevent unapproved executables from running on workstations and servers in scope?
  • Are rulesets maintained, reviewed, and exception-managed?
  • Can you show what happens when something unapproved is blocked?

Weak application control is one of the most common Essential Eight Maturity Level 2 gaps for DISP membership applicants.

2. Patch applications

  • Are internet-facing and high-risk applications patched inside ML2 timeframes?
  • Is vulnerability intake continuous, not quarterly theatre?
  • Are unsupported applications removed or tightly isolated with a documented risk decision?

3. Configure Microsoft Office macro settings

  • Are macros disabled by default for users who do not need them?
  • Is trusted locations / publisher policy deliberate rather than wide open?
  • Can you evidence the setting across the fleet, not one gold-image laptop?

4. User application hardening

  • Are web/office hardening baselines applied and monitored for drift?
  • Have you removed or constrained legacy features attackers still abuse?

5. Restrict administrative privileges

  • Are privileged accounts separate from everyday user accounts?
  • Is local admin removed from standard users?
  • Is privileged access time-bound, logged, and reviewable?

For DISP membership, privilege hygiene is both a cyber control and a governance signal.

6. Patch operating systems

  • Are workstations and servers patched to ML2 expectations?
  • Is there a reliable inventory so "unknown devices" cannot skip patching?
  • Are internet-facing systems prioritised correctly?

7. Multi-factor authentication

  • Is MFA enforced for remote access, privileged access, and key cloud apps?
  • Are SMS-only edge cases understood and minimised?
  • Can you produce coverage reports, not screenshots of one account?

MFA gaps are still one of the fastest ways to fail a serious Essential Eight ML2 readiness review.

8. Regular backups

  • Are critical systems backed up on a defined schedule?
  • Are backups protected from the same identity that administers production?
  • Have restore tests happened recently — with records?

What "good enough for DISP membership" looks like

You do not need a perfect score on day one of planning. You do need:

  • An honest ML2 gap register
  • Funded remediation for the cyber domain
  • Evidence that improves every fortnight
  • Clear ownership between IT, security, and the DISP Security Officer role

Common mistake: scoping cyber too narrowly

Some applicants try to declare a tiny "DISP enclave" while staff handle Defence-related email and files on ordinary corporate systems. Assessors notice. For DISP membership cyber domain work, scope the environment that actually processes the information — then apply Essential Eight Maturity Level 2 there.

Next step

Complete this checklist once with your technical lead in the room. The first honest pass usually reveals whether you are weeks or months from a credible DISP membership cyber submission.

NEXT STEP

Want someone to walk this checklist against your environment?

Ask Skyline AI to line up a short readiness call focused on Essential Eight ML2 and DISP membership.

Talk to Skyline AI
Skyline AI