Skip to main content

DISP Readiness & Essential Eight ML2 Alignment

The Defence Industry Security Program (DISP) exists to ensure organisations within the Defence supply chain appropriately safeguard sensitive information and assets.

For many SMEs, DISP readiness includes demonstrating Essential Eight Maturity Level 2 (ML2) and aligning with relevant guidance from the Australian Information Security Manual (ISM).

DISP readiness is not a checklist exercise. It requires operational controls, defensible documentation, and sustainable governance.

How Essential Eight ML2 Fits Into DISP

For organisations handling Defence-related information, ML2 maturity typically forms part of the security baseline.

ML2 expectations include:

  • Enforced multi-factor authentication
  • Secure configuration of systems and applications
  • Structured patch management
  • Controlled administrative privileges
  • Application control where applicable
  • Logging aligned to monitoring capability

Controls must be implemented consistently and be demonstrable under review.

For a deeper technical breakdown of ML2 maturity expectations, see our Essential Eight ML2 Explained page.

Common Gaps in Defence SMEs

We frequently observe:

  • MFA enabled but inconsistently enforced
  • Privileged accounts poorly segmented
  • Logging enabled but not actively reviewed
  • Patch processes undocumented or reactive
  • Policies written but not operationalised
  • No structured evidence mapping

These gaps often remain invisible until external scrutiny occurs.

Our Structured DISP Readiness Framework

Phase 1 — Gap Assessment

  • ML2 maturity review
  • Infrastructure and identity assessment
  • Control mapping against Essential Eight
  • Risk register baseline
  • Remediation roadmap

Outcome: Clear visibility of required uplift.

Phase 2 — Control Uplift

  • Identity and MFA hardening
  • Administrative privilege restructuring
  • Secure configuration baselines
  • Logging and monitoring uplift
  • Patch governance improvements

Outcome: Operational, enforceable controls.

Phase 3 — Documentation & Evidence

  • System Security Plans
  • Policy refinement
  • Risk management documentation
  • Control evidence mapping
  • Executive-level reporting

Outcome: A defensible posture aligned to Defence expectations.

Phase 4 — Ongoing Governance

  • Periodic ML2 validation
  • Risk register maintenance
  • Executive reporting
  • Continuous improvement

Outcome: Sustainable maturity.