The Australian Signals Directorate's prioritized baseline — eight mitigation strategies across four maturity levels. The November 2023 revision bolstered MFA to require PHISHING-RESISTANT MFA, citing FIDO2/WebAuthn by name, and pulled that requirement down to a lower maturity level. Only eight strategies exist, so most hardware domains here are simply outside its scope.
Australian government entities and their suppliers, AU critical infrastructure
2
control domains mapped
8
products applicable
11
other frameworks cross-mapped
ASD Essential Eight Maturity Model (November 2023)
Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.
Products that satisfy this control:
UL 72 fire-rated safes keep interiors under 350°F through 30-minute to 4-hour furnace exposure — plus explosion and 30-foot drop tests — so original records, storage media, seed-phrase plates, and offline backups survive a facility fire. Distinct from burglary protection: enterprises with records-retention or continuity obligations typically need BOTH ratings on one unit (dual-rated Gardall UL line or TL-rated composite safes — see /safe).
Products that satisfy this control:
Same control in other frameworks: