How I Used OpenVAS to Uplift Essential Eight Maturity For Free!
When it comes to the ASD Essential Eight (E8) , one of the hardest parts isn’t implementing the controls, it’s proving you’re actually maturing. Auditors want evidence, not promises. The good news is that you don’t always need expensive vulnerability management platforms to get there. I’ve previously used OpenVAS (Open Vulnerability Assessment System) , a completely free, open‑source scanner, to help an organisation uplift its E8 maturity. It wasn’t perfect, and I learned a few lessons the hard way, but it worked. Here’s how. The Problem We Needed to Solve We were aiming to uplift maturity for: Patch Applications Patch Operating Systems But we had a few constraints: No budget for commercial vulnerability management tools A requirement for audit‑ready evidence A need to map everything directly to the Essential Eight maturity model OpenVAS ended up being the perfect fit. Why OpenVAS Worked OpenVAS gave us exactly what we needed without the licensing...