Essential Eight Aligned

PlanSuite is aligned with the Australian Signals Directorate's Essential Eight cybersecurity framework — the baseline standard for protecting Australian organisations.

Reference: cyber.gov.au — Essential Eight Maturity Model

What is the Essential Eight?

The Essential Eight is a set of baseline cybersecurity strategies developed by the Australian Signals Directorate (ASD) — Australia's national authority on cybersecurity. It represents the minimum recommended security posture for Australian organisations.

These eight strategies are designed to protect against the most common cyberattacks, including ransomware, data breaches, and unauthorised access. They are widely referenced in government procurement and council IT security requirements across Australia.

The Eight Strategies

How PlanSuite addresses each of the ASD's Essential Eight mitigation strategies.

Aligned

1. Application Control

PlanSuite runs on AWS ECS Fargate — a serverless container platform. Only our verified, containerised application code executes in production. There is no general-purpose operating system where arbitrary applications could be installed or run.

Aligned

2. Patch Applications

Application dependencies are continuously monitored via automated vulnerability scanning and dependency management tools. Updates are applied regularly through our CI/CD pipeline, ensuring known vulnerabilities are patched promptly.

Not Applicable

3. Configure Microsoft Office Macros

PlanSuite is a web application. Users interact entirely through a web browser — there are no Microsoft Office macros, ActiveX controls, or downloadable executables involved in the platform.

Aligned

4. User Application Hardening

The platform does not use Flash, Java applets, or web advertisements. Content Security Policy (CSP) headers are enforced to prevent cross-site scripting and code injection. The attack surface available to end users is minimal by design.

Aligned

5. Restrict Administrative Privileges

Administrative access follows the principle of least privilege. AWS IAM policies restrict access to only what is required. Application-level roles (RBAC) ensure council users only access data within their organisation. There are no shared root accounts.

Aligned

6. Patch Operating Systems

AWS Fargate manages the underlying operating system, including security patches and kernel updates. We do not manage or have access to the host OS — AWS handles this automatically, ensuring patches are applied without delay.

Aligned

7. Multi-Factor Authentication

PlanSuite supports Single Sign-On (SSO) integration with council identity providers (Azure AD / Entra ID, Okta, etc.). MFA is enforced by the council's own IdP — meaning their IT team controls the MFA policy, and staff use their existing credentials. Internal infrastructure access requires MFA via AWS IAM.

Aligned

8. Regular Backups

Database backups are managed by AWS RDS automated backups with point-in-time recovery. Document storage uses AWS S3 with versioning enabled. Backups are encrypted at rest and stored within the Sydney (ap-southeast-2) region.

Why This Matters for Councils

Procurement Ready

Essential Eight alignment is increasingly referenced in Victorian council IT procurement requirements and security assessments.

Australian Standard

Developed by the Australian Signals Directorate (ASD), the Essential Eight is the recognised baseline cybersecurity framework for Australian government and organisations.

Transparent Posture

We openly document our security alignment so councils can assess our posture against their own policies with confidence.

Council SSO Integration

PlanSuite integrates with your council's existing identity provider via Single Sign-On. This means:

  • Your IT team controls MFA policy — not us
  • Staff use their existing credentials — no extra passwords or authenticator apps
  • Instant deprovisioning — someone leaves the council, access is revoked automatically
  • Compatible with Azure AD / Entra ID, Okta, and other SAML/OIDC providers

Australian Data Sovereignty

All PlanSuite data is stored and processed in AWS Sydney (ap-southeast-2). Council data never leaves Australia.

Our infrastructure complies with the Privacy and Data Protection Act 2014 (Vic), the Victorian Protective Data Security Framework (VPDSF), and the Privacy Act 1988 (Cth). For full details, see our Security & Data Protection page and Privacy Policy.

Questions about our security posture?

We're happy to discuss our Essential Eight alignment, provide documentation for procurement processes, or answer any security questions your IT team may have.