Security requirements

Make application maintenance repeatable for Essential Eight priorities

For Australian organizations aligning with the Essential Eight, a maturity target creates work that continues with each software release and configuration change. Devicie helps your team maintain supported applications, review reported installation results and preserve agreed settings in managed policies.

From target to work

Turn the target into work your teams can sustain

ASD's Essential Eight maturity model includes requirements for discovering assets, assessing vulnerabilities and applying application updates. The required activities and timing depend on the selected maturity level and the situation.

IT and security need to agree which systems and applications are in scope, what takes priority and how the work will be carried out.

Devicie contributes to selected maintenance activities within that process. Your organization retains responsibility for assessing vulnerabilities, setting priorities and demonstrating the requirements of its target level.

Application inventory

Start with the applications on your devices

Devicie reports installed applications and versions on supported devices, including software installed in user context.

Use that information to compare what is present with what the organization expects, identify version sprawl and establish which applications should be managed.

Application inventory provides context for maintenance. Your vulnerability-assessment process determines which findings require action and how urgently.

Packaging work

Reduce the preparation work behind supported updates

Devicie maintains application packages in its catalog. Your team can deploy supported packages through Intune and review reported installation results.

For your own software, submit the installer and requirements through Devicie's packaging workflow. The reviewed path includes a person checking the submission and testing that validates installation. Submit subsequent installers when new versions need packaging.

Your teams retain rollout decisions, business acceptance and follow-up on exceptions.

The full sequence

Measure the full update process

The maturity model's patching requirements concern applying updates or appropriate mitigations. A package becoming available is an intermediate step. Package availability alone cannot establish that a patching requirement has been met. Devicie reporting refreshes daily. Use the additional checks your organization needs when validating a specific deadline. Review the full sequence for the applications in scope.

01

When the relevant release became available.

02

When a supported package was ready.

03

When deployment was assigned.

04

What installation was reported.

05

Which devices or applications still require action.

Managed configuration

Keep agreed settings under ongoing management

Choose a relevant Essential Eight requirement and identify the supported managed policies that contribute to it. Agree the settings, owners and validation before relying on them in your program.

Devicie corrects drift in those managed policies and provides readable notifications. Use the pause, edit and resume workflow for deliberate changes, within your organization's authorization process.

Inspect the specific contribution and the remaining requirement together. A corrected policy is one operational result; your maturity assessment needs the full applicable implementation and evidence.

The Essential Eight Overview report — mitigation strategies by maturity level, with the control table beneath recording status, policy name and assignment results.
The Essential Eight Overview report — mitigation strategies by maturity level, with the control table beneath recording status, policy name and assignment results.

The wider program

Keep the wider program in view

The eight mitigation strategies are intended to work together. ASD advises organizations to work toward the same maturity level across all eight before progressing further.

Devicie's contribution here concerns supported application maintenance and managed configuration. Your wider program still needs coverage for the other applicable requirements, with clear owners and assessment evidence.

Use reported application results and policy notifications as inputs to that review, with their scope and timing understood.

Questions we get asked

Does Devicie give us an Essential Eight maturity level?

No. The capabilities described here support selected operational activities. Achievement of a maturity level depends on your implementation and assessment of the relevant requirements.

Does the application catalog replace vulnerability scanning?

No. Catalog coverage and application inventory do not establish vulnerability detection or risk-based prioritization. Your security process supplies those decisions.

Can we use the Intune Health Assessment as an Essential Eight assessment?

No. Its Intune configuration findings can inform your work, but it is not an assessment of all Essential Eight requirements.

How should we evaluate Devicie for our program?

Choose a defined application set and relevant managed policies. Walk through the supported workflows, available outputs, timing and responsibilities that remain.

Review the maintenance behind your target

Bring the requirements your team is working toward and the applications it maintains. See where Devicie can reduce recurring preparation and correction work.