SD-WAN and the Essential Eight: How SD-WAN Supports ASD Compliance
The Australian Signals Directorate's Essential Eight has become the de facto cybersecurity baseline for Australian organisations. While many businesses focus on endpoint controls, SD-WAN plays a meaningful role in achieving and maintaining higher maturity levels across several of the eight strategies.
Essential Eight Quick Recap
The ASD Essential Eight are eight mitigation strategies prioritised to protect organisations from cyber threats:
- Application Control
- Patch Applications
- Configure Microsoft Office Macros
- User Application Hardening
- Restrict Administrative Privileges
- Patch Operating Systems
- Multi-Factor Authentication
- Regular Backups
Four of these have direct network-layer implications where SD-WAN strengthens your posture.
Strategy 1: Application Control
ASD requirement: Prevent execution of unapproved applications. At network level, this extends to controlling which network applications are permitted.
SD-WAN contribution:
- Application identification: SD-WAN's deep packet inspection identifies thousands of applications by traffic signature
- Application blocking: Deny access to specific applications at network layer — peer-to-peer, unapproved cloud storage, shadow IT
- Visibility: Audit logs of all application usage across every site
- Policy enforcement: Rules applied consistently across all branch locations without per-site firewall configuration
Strategy 5: Restrict Administrative Privileges
ASD requirement: Limit who can administer systems, and validate those administrators regularly.
SD-WAN contribution:
- ZTNA enforcement: Administrative access to systems granted per-application, not per-network-segment
- Privileged access management: SD-WAN integrated with PAM tools for jump-host access control
- MFA at network boundary: Require MFA before accessing management VLANs or admin interfaces
- Audit trails: All administrative access logged with user identity, timestamp, and source
Strategy 7: Multi-Factor Authentication
ASD requirement: MFA for remote access, privileged actions, and access to important data.
SD-WAN contribution:
- ZTNA enforcement: SD-WAN SASE stack mandates MFA before any remote application access
- VPN replacement: Modern ZTNA inherently requires MFA — removes legacy VPN single-factor exposure
- Continuous authentication: Re-verification triggers on anomalous behaviour
- Device posture checks: Combines "something you know" (MFA) with "device you own" (MDM compliance)
Strategy 2 & 6: Patch Applications and Operating Systems
ASD requirement: Apply security patches within defined timeframes based on risk.
SD-WAN contribution:
- Patch traffic prioritisation: SD-WAN ensures Windows Update and SCCM traffic gets bandwidth, not throttled by other apps
- Direct update routing: Patch servers and Microsoft Update direct internet access — no bottleneck
- SD-WAN firmware management: Centralised firmware updates across all appliances via InControl
- Network segmentation: Unpatched devices isolated to separate VLAN until patched
Maturity Level Mapping
Maturity Level 1
- SD-WAN application visibility and basic blocking: contributes to Application Control ML1
- ZTNA with MFA: directly addresses MFA ML1
Maturity Level 2
- Application-aware traffic policies: Application Control ML2
- ZTNA with device posture: MFA ML2
- Privileged access management integration: Administrative Privileges ML2
Maturity Level 3
- Phishing-resistant MFA via FIDO2 enforced at network edge
- Micro-segmentation preventing lateral movement
- AI-powered anomaly detection for compromised credentials
What SD-WAN Cannot Do
Be clear-eyed about limits — SD-WAN is a complement, not a replacement for endpoint controls:
- Cannot control which applications execute on endpoints (that's EDR/application whitelisting)
- Cannot patch software on devices (that's SCCM/Intune)
- Cannot control macro settings in Office (that's Group Policy)
- Cannot perform backup operations (that's dedicated backup platforms)
Essential Eight Assessment Support
When preparing for an Essential Eight assessment, SD-WAN provides valuable evidence:
- Application control logs demonstrating blocked applications
- Access logs showing MFA enforcement
- Network segmentation documentation
- Audit trails for privileged access
Affinity MSP: Essential Eight Network Controls
Affinity MSP aligns SD-WAN deployments to Essential Eight requirements:
- Gap analysis: Identify where SD-WAN strengthens your Essential Eight posture
- Evidence packages: Documentation ready for assessors
- ZTNA deployment: Addresses MFA and privilege restriction requirements
- Compliance reporting: Regular reports aligned to ASD framework
Conclusion
SD-WAN is a meaningful contributor to Essential Eight compliance, particularly for Application Control, MFA, and Restriction of Administrative Privileges. Australian organisations pursuing Maturity Level 2 or 3 will find that a properly configured SD-WAN + SASE stack removes significant compliance gaps at the network layer — evidence that assessors can see and validate.
Align Your Network to the Essential Eight
Get an Essential Eight gap analysis focused on network-layer controls and SD-WAN's role in your compliance program.
Book an Essential Eight Review