Ask your ICT lead for a list of every system the school couldn’t operate without. If the answer takes longer than it should, that’s the gap this edition is about.
Every other control in the Essential Eight quietly assumes that list already exists. Patch operating systems assumes you know which devices matter most. Regular backups assumes you know what’s worth restoring first. Restrict administrative privileges assumes you know which accounts touch the systems that would actually hurt the school if they were compromised. None of that prioritisation is possible without a register of what you’re protecting, and a genuinely large number of schools are running their entire security programme without one.
The governance gap, not the IT gap
This sits in ICT because someone has to type it into a spreadsheet, but the decision it represents doesn’t belong to ICT. Deciding which systems are “crown jewels”, the small subset that would genuinely hurt the school if compromised, lost, or taken offline, as distinct from everything else that’s merely important, is a risk judgement. It requires knowing what a two-week outage of the student information system would cost against a two-week outage of the guest wifi, and only the people who hold budget and consequence can make that call credibly.
Without that register, a board asking “what’s our biggest cyber risk” gets an answer built on whatever the IT team happens to remember that week, not a documented, defensible position. That’s the version of this gap worth raising at board level: not “have we listed our servers”, but “can the school demonstrate, in writing, what it has decided matters most, and who signed off on that list”.
Why this isn’t optional once you look at the other seven controls
The Essential Eight Maturity Model requires an automated method of asset discovery, at every maturity level, to support vulnerability scanning for the patch applications and patch operating systems controls specifically. That detail came up via search rather than a direct pull from the primary ACSC document, so it’s worth confirming the exact wording against the current Essential Eight Maturity Model before it goes into a formal assessment. But the practical point stands regardless of the exact wording: a school cannot legitimately claim maturity against two of the eight controls without an asset inventory sitting underneath them. This is the register that either makes the rest of the series usable, or leaves every other control resting on guesswork.
The population fork this register has to carry
A school’s crown jewels register isn’t one list. It’s at least two, and treating it as one is the most common way this exercise goes wrong.
Staff and admin systems, finance, HR, the student information system backend, Global Admin, sit in one risk category: compromise there tends to mean fraud, operational disruption, or a breach of employee data. Student-facing systems, the LMS, student information portals, assessment platforms, sit in a different one entirely: they hold personal information on children, often at a much larger scale, and under the additional obligations that come with that. A register built by IT for IT has a habit of quietly under-representing the second category, because nobody in the exercise thought to ask the LMS vendor what they’re actually storing. Split the list on that line from the start, or the two risk profiles will get flattened into one column and the student-facing gap will stay invisible until something goes wrong.
Where the free resources come from, and their limits
There isn’t an ACSC-branded template for this specific exercise. The UK’s National Cyber Security Centre publishes two free, practical resources that cover the same ground: Identifying the critical assets in your organisation, from the Cyber Security Toolkit for Boards, which sets out the crown jewels concept directly and lists the minimum fields worth recording, and Asset management from the 10 Steps to Cyber Security collection, which covers maintaining the register over time, including data owners and third-party or SaaS dependencies.
Neither resource is Australian or education-specific. The concepts transfer cleanly, and there’s no cost or licence tier attached to using a spreadsheet, so this is one of the few controls in the series with no licence fork to navigate. But if a board member asks whether the methodology is ACSC-endorsed, the honest answer is no. It’s sound practice borrowed from a comparable national authority, not an Australian government product.
Where this leaves you
The next few editions in this series, application control, patching, backups, all assume this register exists underneath them. If it doesn’t, none of those controls can be prioritised with any confidence, only applied evenly across a fleet nobody’s actually ranked by importance.
The question worth putting to your executive team this term isn’t whether the school has good IT. It’s whether the school can produce, in writing, a list of what it has decided matters most, and who signed off on that decision.