Ask your ICT lead for a list of every system the school couldn’t operate without. If the answer takes longer than it should, that’s the gap this edition is about.

Every other control in the Essential Eight quietly assumes that list already exists. Patch operating systems assumes you know which devices matter most. Regular backups assumes you know what’s worth restoring first. Restrict administrative privileges assumes you know which accounts touch the systems that would actually hurt the school if they were compromised. None of that prioritisation is possible without a register of what you’re protecting, and a genuinely large number of schools are running their entire security programme without one.

The governance gap, not the IT gap

This sits in ICT because someone has to type it into a spreadsheet, but the decision it represents doesn’t belong to ICT. Deciding which systems are “crown jewels”, the small subset that would genuinely hurt the school if compromised, lost, or taken offline, as distinct from everything else that’s merely important, is a risk judgement. It requires knowing what a two-week outage of the student information system would cost against a two-week outage of the guest wifi, and only the people who hold budget and consequence can make that call credibly.

Without that register, a board asking “what’s our biggest cyber risk” gets an answer built on whatever the IT team happens to remember that week, not a documented, defensible position. That’s the version of this gap worth raising at board level: not “have we listed our servers”, but “can the school demonstrate, in writing, what it has decided matters most, and who signed off on that list”.

Why this isn’t optional once you look at the other seven controls

The Essential Eight Maturity Model requires an automated method of asset discovery, at every maturity level, to support vulnerability scanning for the patch applications and patch operating systems controls specifically. That detail came up via search rather than a direct pull from the primary ACSC document, so it’s worth confirming the exact wording against the current Essential Eight Maturity Model before it goes into a formal assessment. But the practical point stands regardless of the exact wording: a school cannot legitimately claim maturity against two of the eight controls without an asset inventory sitting underneath them. This is the register that either makes the rest of the series usable, or leaves every other control resting on guesswork.

The population fork this register has to carry

A school’s crown jewels register isn’t one list. It’s at least two, and treating it as one is the most common way this exercise goes wrong.

Staff and admin systems, finance, HR, the student information system backend, Global Admin, sit in one risk category: compromise there tends to mean fraud, operational disruption, or a breach of employee data. Student-facing systems, the LMS, student information portals, assessment platforms, sit in a different one entirely: they hold personal information on children, often at a much larger scale, and under the additional obligations that come with that. A register built by IT for IT has a habit of quietly under-representing the second category, because nobody in the exercise thought to ask the LMS vendor what they’re actually storing. Split the list on that line from the start, or the two risk profiles will get flattened into one column and the student-facing gap will stay invisible until something goes wrong.

Where the free resources come from, and their limits

There isn’t an ACSC-branded template for this specific exercise. The UK’s National Cyber Security Centre publishes two free, practical resources that cover the same ground: Identifying the critical assets in your organisation, from the Cyber Security Toolkit for Boards, which sets out the crown jewels concept directly and lists the minimum fields worth recording, and Asset management from the 10 Steps to Cyber Security collection, which covers maintaining the register over time, including data owners and third-party or SaaS dependencies.

Neither resource is Australian or education-specific. The concepts transfer cleanly, and there’s no cost or licence tier attached to using a spreadsheet, so this is one of the few controls in the series with no licence fork to navigate. But if a board member asks whether the methodology is ACSC-endorsed, the honest answer is no. It’s sound practice borrowed from a comparable national authority, not an Australian government product.

Where this leaves you

The next few editions in this series, application control, patching, backups, all assume this register exists underneath them. If it doesn’t, none of those controls can be prioritised with any confidence, only applied evenly across a fleet nobody’s actually ranked by importance.

The question worth putting to your executive team this term isn’t whether the school has good IT. It’s whether the school can produce, in writing, a list of what it has decided matters most, and who signed off on that decision.

Best Practice - This is the way

Ask for the list before you ask for anything else. A board or executive team that can’t see a documented crown jewels register can’t meaningfully sign off on any other part of the security programme, because there’s nothing to prioritise against.
Split staff and admin from student-facing from the outset. Two lists, not one, with the student-facing list built with input from whoever manages the LMS and SIS relationships, not just IT.
Capture five fields per system. Where it’s hosted, who’s responsible for it, what data sits on it, how it’s backed up, and how it’s accessed. That’s enough for a defensible first pass.
Put an owner and a date on the register itself. A register nobody’s responsible for maintaining goes stale within a term, and a stale register is functionally the same as no register once it’s more than a few months old.
Use it as the entry point for every other control conversation. When someone proposes a patching cadence, a backup schedule, or an access review, ask which systems on the register it actually covers, and which it doesn’t.
Don’t wait for a perfect list before you start. A partial register in use today outperforms a comprehensive one that’s still six months from finished.

Daniel Johns is a CRISC-certified virtual CISO and GRC advisor, Founder of Coastal Cyber, and a former member of the ISACA Global Advisory Council and CompTIA Executive Council ANZ. He works with independent and faith-based schools, healthcare providers, financial services, technology businesses, and MSPs across Southeast Queensland on privacy, cyber security, and governance.

If your school’s privacy and cyber posture needs a clear-eyed assessment, book a 20-minute conversation.