Security requirements
Make application maintenance repeatable for Essential Eight priorities
For Australian organizations aligning with the Essential Eight, a maturity target creates work that continues with each software release and configuration change. Devicie helps your team maintain supported applications, review reported installation results and preserve agreed settings in managed policies.
From target to work
Turn the target into work your teams can sustain
ASD's Essential Eight maturity model includes requirements for discovering assets, assessing vulnerabilities and applying application updates. The required activities and timing depend on the selected maturity level and the situation.
IT and security need to agree which systems and applications are in scope, what takes priority and how the work will be carried out.
Devicie contributes to selected maintenance activities within that process. Your organization retains responsibility for assessing vulnerabilities, setting priorities and demonstrating the requirements of its target level.
Application inventory
Start with the applications on your devices
Devicie reports installed applications and versions on supported devices, including software installed in user context.
Use that information to compare what is present with what the organization expects, identify version sprawl and establish which applications should be managed.
Application inventory provides context for maintenance. Your vulnerability-assessment process determines which findings require action and how urgently.
Packaging work
Reduce the preparation work behind supported updates
Devicie maintains application packages in its catalog. Your team can deploy supported packages through Intune and review reported installation results.
For your own software, submit the installer and requirements through Devicie's packaging workflow. The reviewed path includes a person checking the submission and testing that validates installation. Submit subsequent installers when new versions need packaging.
Your teams retain rollout decisions, business acceptance and follow-up on exceptions.
The full sequence
Measure the full update process
The maturity model's patching requirements concern applying updates or appropriate mitigations. A package becoming available is an intermediate step. Package availability alone cannot establish that a patching requirement has been met. Devicie reporting refreshes daily. Use the additional checks your organization needs when validating a specific deadline. Review the full sequence for the applications in scope.
When the relevant release became available.
When a supported package was ready.
When deployment was assigned.
What installation was reported.
Which devices or applications still require action.
Managed configuration
Keep agreed settings under ongoing management
Choose a relevant Essential Eight requirement and identify the supported managed policies that contribute to it. Agree the settings, owners and validation before relying on them in your program.
Devicie corrects drift in those managed policies and provides readable notifications. Use the pause, edit and resume workflow for deliberate changes, within your organization's authorization process.
Inspect the specific contribution and the remaining requirement together. A corrected policy is one operational result; your maturity assessment needs the full applicable implementation and evidence.
The wider program
Keep the wider program in view
The eight mitigation strategies are intended to work together. ASD advises organizations to work toward the same maturity level across all eight before progressing further.
Devicie's contribution here concerns supported application maintenance and managed configuration. Your wider program still needs coverage for the other applicable requirements, with clear owners and assessment evidence.
Use reported application results and policy notifications as inputs to that review, with their scope and timing understood.
Questions we get asked
Does Devicie give us an Essential Eight maturity level?
No. The capabilities described here support selected operational activities. Achievement of a maturity level depends on your implementation and assessment of the relevant requirements.
Does the application catalog replace vulnerability scanning?
No. Catalog coverage and application inventory do not establish vulnerability detection or risk-based prioritization. Your security process supplies those decisions.
Can we use the Intune Health Assessment as an Essential Eight assessment?
No. Its Intune configuration findings can inform your work, but it is not an assessment of all Essential Eight requirements.
How should we evaluate Devicie for our program?
Choose a defined application set and relevant managed policies. Walk through the supported workflows, available outputs, timing and responsibilities that remain.
Review the maintenance behind your target
Bring the requirements your team is working toward and the applications it maintains. See where Devicie can reduce recurring preparation and correction work.