[E1]
Security Overview
Australian Defence Projects

Building a secure
home for Defence
tender information.

This overview describes E1's security posture for Australian Defence tender information. Control positions are current assessments for review, not audited statements. PROTECTED information is not yet formally supported. Prepared July 2026. Commercial in confidence.

What you can store

What information can be used with E1?

E1 supports the markings that commercial Defence tender packages typically carry. The boundary below sets out what may and may not be placed on the platform.

Information markingE1 position
OFFICIALSupported
OFFICIAL: SensitiveSupported, subject to customer and project requirements
PROTECTEDNot yet formally supported; E1 is approaching the required support
SECRETNot supported
TOP SECRETNot supported
Met In progress Gap
Clarification
Platform security

How E1 protects tender information

E1 applies security controls across the platform. Access to each tender remains controlled by the customer and the permissions they assign.

Access stays with the customer. Access to each tender is invite-only and strictly need-to-know. Customers assign and revoke permissions themselves, and every action is captured in a full audit trail, so you always know who has seen what.

Strong authentication. Every user signs in with multifactor authentication, and access is limited to trusted, managed devices rather than passwords alone.

Encryption in transit and at rest. Tender documents are encrypted throughout their lifecycle using strong, current algorithms, with managed and access-restricted keys.

Australian data residency. E1 stores Australian document data in AWS's Sydney region, and these documents are not sent to overseas processors. Customers should confirm any additional residency, sovereignty or personnel-access requirements in their contract.

Not used in public AI. Defence tender documents are never used to train or run public AI models.

Restricted, monitored administration. Administrative access is least-privilege, separated from everyday accounts and granted only when needed. The platform is continuously monitored, with security event detection and alerting.

Patched and recoverable. Vulnerabilities are tracked and patched across the platform. Backups are immutable and replicated to a separate, isolated store, with recovery tested on a defined cycle.

Audited and governed. Access and activity are captured in full audit trails, under an information security management system aligned with ISO/IEC 27001.

The sections that follow set these controls out in depth, including E1's strong self-assessed alignment with the ACSC Essential Eight.

Sensitivity and security maturity

How information sensitivity maps to security maturity

Australian Government information markings indicate the potential impact if information is compromised. As the sensitivity increases, the expected security maturity of the systems handling that information also increases. The Essential Eight maturity model provides a practical benchmark for this progression, with higher maturity levels designed to withstand more capable and persistent adversaries.

Essential Eight benchmarkInformation typeSecurity expectation
Maturity Level 1OFFICIALProtects against common, opportunistic attacks using publicly available tools and known vulnerabilities.
Maturity Level 2OFFICIAL: SensitiveProtects against more focused adversaries that invest additional time, use targeted phishing and attempt to bypass common security controls.
Maturity Level 3PROTECTEDProtects against adaptive, targeted adversaries using stronger techniques. Supported by applicable ISM controls, formal governance and independent assurance.

Why the maturity level matters

The classification does not operate as a standalone label. It indicates the level of harm that could result from compromise, and therefore informs the strength of security controls expected around the information. As information moves from OFFICIAL to OFFICIAL: Sensitive and then PROTECTED, organisations are expected to apply progressively stronger controls across areas such as:

The Essential Eight therefore provides a clear way to understand how security expectations increase alongside the sensitivity of Defence information.

i

A benchmark, not a universal rule. This mapping is a useful guide, but the controls actually required are determined by the PSPF, the ISM, Defence requirements, the contract and the system's risk assessment. The Essential Eight covers only eight mitigation strategies; the ISM contains many more, as the next page sets out.

Beyond the Essential Eight

Requirements beyond the Essential Eight

Meeting the Essential Eight is necessary but not sufficient. Each marking carries handling obligations under the Protective Security Policy Framework and other frameworks that go well beyond the eight mitigation strategies.

OFFICIAL

Supported on E1
  • Controlled access to each document
  • Appropriate, encrypted storage
  • Records retention with a full audit trail
  • Secure disposal when no longer required
  • Protection from unauthorised viewing or disclosure
  • Encrypted transmission over public networks

OFFICIAL: Sensitive adds

Supported on E1
  • All controls from OFFICIAL
  • Protective marking retained on documents
  • Stricter need-to-know, invite-only access
  • Stronger transfer and storage controls
  • Audit trail supporting privacy, legal-privilege and commercial-sensitivity handling

PROTECTED adds

Approaching
  • All controls from OFFICIAL: Sensitive
  • Defence documents are never placed into public AI services
  • Storage and processing remain within Australia
  • Broader ISM controls beyond the Essential Eight
  • Stronger personnel and physical security
  • Controlled administration, transfer and disposal processes
  • Independent system assessment and authorisation

Each level inherits all controls of the level below it. Contract or project-specific instructions may impose additional residency, personnel, clearance or handling requirements, which remain the customer's responsibility to confirm.

E1 self-assessment

E1's Essential Eight Maturity Level Analysis

E1 already meets or substantially meets most Maturity Level 3 requirements. The assessment below sets out each strategy across all three maturity levels, with E1's self-assessed status for every requirement.

This is E1's own gap analysis

E1 is not yet formally certified or independently assessed against the Essential Eight. The positions shown are E1's own self-assessment, and will be confirmed by evidence and, where required, independent assessment.

1

Patch applications

ML1ML2ML3
  • Formal, documented patch management processML1
  • Applications continuously scanned for vulnerabilitiesML1
  • Critical internet-facing vulnerabilities patched within 48 hoursML1
  • Unsupported applications removedML1
  • All applications patched within one month of releaseML2
  • All applications scanned fortnightly or betterML2
  • Critical patches for endpoints and common apps within 48 hoursML3
  • Firmware kept current across devices and network equipmentML3
2

Multi-factor authentication

ML1ML2ML3
  • MFA enforced for users of internet-facing services with sensitive dataML1
  • MFA required for all users, across services and devicesML2
  • Successful and unsuccessful authentication events centrally loggedML2
  • Access requires a verified, approved device, defeating credential-only phishingML2
  • MFA required for access to sensitive data repositoriesML3
  • Authentication logs analysed across services and devicesML3
MetIn progressGap Self-assessed level completion · strategies 3 to 4 on page 7
Essential Eight · E1 gap analysis (continued)

Privilege and application control

3

Restrict administrative privileges

ML1ML2ML3
  • Separate privileged and unprivileged accounts for administratorsML1
  • Privileged accounts blocked from internet, email and web servicesML1
  • Privileged access validated when first requestedML1
  • Privileged access revalidated at least annuallyML2
  • Privileged access events centrally loggedML2
  • Privileged access automatically disabled after a period of inactivityML2
  • Just-in-Time administration used to grant access only when neededML3
  • Administrative tasks restricted to managed, controlled devicesML3
  • Credentials protected against theft and reuseML3
4

Application control

ML1ML2ML3
  • Execution control enforced on every deviceML1
  • Application control enforced on internet-facing serversML2
  • Allowed and blocked execution events centrally loggedML2
  • Known-malicious applications blockedML2
  • Execution ruleset reviewed at least annuallyML2
  • Application control extended across all servers, including internalML3
  • Execution of vulnerable drivers and kernel components blockedML3
MetIn progressGap Strategies 5 to 6 on page 8
Essential Eight · E1 gap analysis (continued)

Macros and application hardening

5

Restrict Office macros

ML1ML2ML3
  • Macros from untrusted sources blockedML1
  • Users cannot change macro security settingsML1
  • Macro and file behaviour scanned before executionML1
  • Macro calls to high-risk system interfaces blockedML2
  • Macros only run from a trusted, controlled contextML3
6

User application hardening

ML1ML2ML3
  • Web browsers block advertisements from the internetML1
  • Web browsers block Java from the internetML1
  • Endpoint command-line activity centrally loggedML2
  • Legacy and unneeded browser components removedML2
  • Productivity applications blocked from spawning malicious processesML2
  • Legacy and high-risk scripting components removed or restrictedML3
MetIn progressGap Strategies 7 to 8 on page 9
Essential Eight · E1 gap analysis (continued)

Operating systems and backups

7

Patch operating systems

ML1ML2ML3
  • Operating systems on all devices scanned for vulnerabilities continuouslyML1
  • Critical operating-system vulnerabilities patched promptlyML1
  • Only vendor-supported operating systems in useML1
  • Server operating systems patched within one monthML2
  • Fortnightly-or-better operating-system vulnerability scanningML2
  • Critical operating-system patches within 48 hoursML3
  • Firmware kept current across devices and network equipmentML3
8

Regular backups

ML1ML2ML3
  • Regular backups of important data, software and configurationML1
  • Backups retained in line with business continuity requirementsML1
  • Restoration of backups tested on a defined cycleML1
  • Unprivileged accounts cannot access, modify or delete backupsML1
  • Privileged accounts, including administrators, cannot modify or delete backupsML2
  • Backups immutable during the retention period, replicated to a separate storeML3
MetIn progressGap Consolidated summary on page 10
Essential Eight · At a glance

Essential Eight maturity summary

E1's self-assessed status at each maturity level, strategy by strategy. This is E1's own gap analysis, not a formal or independent assessment.

E8 strategy areaML1ML2ML3
Patch applications
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Office macros
User application hardening
Patch operating systems
Regular backups
Met (self-assessed) In progress

The honest position

E1's controls already extend significantly beyond the requirements normally associated with OFFICIAL: Sensitive information. Most of the technical foundation for Essential Eight Maturity Level 3 is in place.

The remaining work is concentrated in evidence, formalisation and several specific control refinements, rather than the absence of fundamental security capabilities.

Formal PROTECTED support

What remains for formal PROTECTED support

Reaching and evidencing Essential Eight Maturity Level 3 is an important part of supporting PROTECTED information, but it is not the only requirement. E1 must also determine and implement the applicable ISM controls, prepare the required security documentation and complete an independent IRAP assessment.

Already in place

  • A strong platform foundation: onshore hosting, encryption, tight access control and monitoring
  • Essential Eight controls operating and reaching into Maturity Level 3
  • System architecture and data-flow documentation prepared
»

Remaining before formal PROTECTED support

  • Reach and formally evidence Essential Eight Maturity Level 3
  • Logical separation of PROTECTED information from lower-sensitivity systems and data
  • Network segmentation and controlled gateways between security domains
  • Encryption using ASD Approved Cryptographic Algorithms and Protocols
  • Broader ISM controls across system administration, monitoring, secure development, data transfers, media handling and backups
  • Formal system authorisation: a documented security assessment with an authorising officer accepting the residual risk
  • An independent IRAP assessment at the PROTECTED classification (Stage 1 and Stage 2)
  • Australian hosting and control, addressing foreign ownership, legal control and personnel access
  • Security-cleared personnel for anyone with access, including cloud administrators and support staff
  • Need-to-know access with least privilege and controlled privileged access
  • AI use confined to an appropriately authorised environment
  • Approved handling and transfer processes that retain protective markings
  • Physical security appropriate to PROTECTED, including remote-work controls
  • Incident reporting through Defence and contractual security channels
  • Defence-specific obligations where imposed by contract (DISP membership, DSPF controls, nationality restrictions, security officers)
i

Informing a risk assessment. E1 does not hold IRAP certification. Customers should review their own requirements and use this document to inform a risk assessment before uploading PROTECTED information. E1 is close on the Essential Eight and has much of the underlying platform capability; formal PROTECTED support would still involve independent assessment.

Shared responsibility

Shared responsibility

E1 secures the platform. Customers remain responsible for how they classify, share and manage their own information.

  • Classify information correctly before uploading it
  • Restrict tender access to authorised recipients
  • Remove access when it is no longer required
  • Follow any project-specific handling instructions
  • Confirm contractual DISP, residency, personnel and clearance requirements
i

Where a tender, contract or security instruction expressly requires DISP membership, an accredited system, Australian-based personnel, security clearances or another specific control, customers should confirm those requirements with their Defence contract manager or legal adviser before uploading the information.

In summary

E1 supports OFFICIAL: Sensitive today. Its platform already implements strong security controls, including near-complete alignment with Essential Eight Maturity Level 3. This provides a substantial foundation for future PROTECTED support, although further evidence, ISM alignment and independent assessment are still required.

This statement describes E1's standard platform scope. It is not a determination that every Defence project or contract permits the use of E1.