Security Assessment Advisor

ISM, Essential Eight and OWASP knowledge, where you need it.

Your AI. Running on a laptop, a server or a cloud you own. Security Assessment Advisor puts the ASD Information Security Manual, the Essential Eight and OWASP ASVS inside the assistant your team already uses. Look up a control, scope an assessment, be walked through it, and export the paperwork. Every answer quoted from the published release, never from the model’s memory.

Book a 25-minute demo Start a 30-day trial Works in Microsoft 365 Copilot, Copilot Studio, VS Code, Claude Desktop and your CI pipeline.
  • ASD ISM, all classifications, plus the OT overlay
  • Essential Eight, Maturity Levels 1–3
  • OWASP ASVS 5.0, Levels 1–3
  • Canberra built, runs where you say
Microsoft 365 Copilot · Security Assessment Advisor
What does ISM-1504 require, and is it in Essential Eight Maturity Level 1?
“Multi-factor authentication is used to authenticate human users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.”
ISM-1504E8_ML1E8_ML2E8_ML3PROTECTED+4 baselines

Yes. It sits under Guidelines for system access › Multi-factor authentication and applies at every classification and all three Essential Eight maturity levels. Want to record how your system meets it?

Quoted from ISM release v2026.09.4, published 4 Sep 2026.

Why now

Stop running security assessments from a PDF, a spreadsheet and somebody’s memory.

The ISM changes several times a year. ASVS 5.0 rewrote most of 4.0. A general-purpose AI assistant will happily quote you a control number that no longer exists, and an assessor with a 1,100-row spreadsheet will happily miss one that does.

The standard moves. Your evidence doesn’t.

The Advisor loads the current ISM release, tells you when a newer one lands, and can show you exactly which controls were added, removed or reworded between two releases.

AI that can’t make things up.

Nothing is answered from training data. Every control id, requirement id and quoted sentence comes from the release the server has loaded, and the release is stamped on the answer.

Silence is not evidence.

A control you haven’t assessed is counted as a gap, not quietly dropped. Coverage percentages and top gaps are always complete, so nobody is surprised at the IRAP stage.

Built for Microsoft. (And for Claude.)

It lives where your people already work.

No new portal to log into. The Advisor connects over the open Model Context Protocol, so the same tools show up in Copilot, Claude and your developer tooling. Where the client can draw a form or a dashboard, you get one. Where it can’t, you get the identical workflow in plain text.

Microsoft 365 Copilot VS Code Copilot Claude Desktop claude.ai Copilot Studio Claude Code Cline / Roo Code GitHub Actions Azure DevOps
Interactive forms and dashboardsSame workflow, as text

Ask AI anything

Ask the question you’d ask a senior assessor.

Plain English in. Real control ids out. Attach the SSP, policy, pen-test report or screenshot you already have and the Advisor maps it to controls, checking every id against the live catalogue and rejecting anything it can’t verify.

Which Essential Eight Maturity Level 2 controls cover application control?
Show me every PROTECTED control about TLS, and what changed in the latest release.
Here’s our SSP. Where are the gaps against PROTECTED?Attach a Word document, spreadsheet or PDF
Which ASVS Level 2 requirements apply to session management in our API?
What does IEC 62443 expect at Purdue Level 3, and which ISM controls carry it?

The assessment loop

One conversation, from scoping to paperwork.

An assessment is rarely finished in one sitting. Your progress comes back as a file you own. Hand it back tomorrow, next week or to a colleague, and pick up exactly where you left off.

Scope

Name the system, pick a baseline (PROTECTED, an Essential Eight level, or an ASVS level) and answer a few qualifying questions.

Walk through

The assistant puts each control in front of you in small batches and records your status, justification and evidence.

Save and resume

Get the work-in-progress back as a file. No server-side session to time out, nothing lost to a dropped connection.

See where you stand

Coverage, counts by status and the top gaps, as a live dashboard or as text.

Export

SSP annex, OSCAL POA&M, ASVS checklist, or a Word / PowerPoint report, stamped with release and classification.

From connected to a draft SSP annex

One week. Not one quarter.

Minute 10

Connect

Add the connector to Copilot or Claude, sign in with your Entra ID, ask your first question.

Hour 1

Scope your first system

Baseline chosen, qualifying questions answered, the control set in front of you.

Day 1

Draft from what you already have

Attach the existing SSP and pen-test report. Watch the coverage figure move as the assistant maps them.

Week 1

Paperwork out

SSP annex workbook and POA&M in the assessor’s inbox, gaps assigned with owners and target dates.

Acme OT platform · PROTECTEDISM v2026.09.4 · example figures
62%coverage
668implemented
121partially
288gaps
  • ISM-1490Application control on serversPartial
  • ISM-1504MFA for online servicesUnassessed
  • ISM-0580Event logging retentionUnassessed

Stop guessing your posture

The paperwork your assessor actually asked for.

The gap analysis is the intelligence. The exports are what you put in front of your board, your IRAP assessor or your CISO. Both come out of the same conversation.

.xlsxSSP annex workbookCover, Controls and Unknown items sheets. OT columns included by default.
.jsonOSCAL 1.1 POA&MOne item, observation and risk per gap. Machine-readable for your GRC tooling.
.xlsxASVS checklistLevel-based gap analysis for a web app or API.
.docx · .pptx · .md · .csvNarrative reportWord for the assessor, PowerPoint for the steering committee.

Essential Eight

Know your maturity level before the auditor does.

The Essential Eight is where most Australian agencies and their suppliers start, and where most of the reporting pressure sits. The Advisor treats each maturity level as a baseline in its own right: scope an assessment against ML1, ML2 or ML3, walk the controls that apply, and see the coverage figure for that level, not the whole ISM. Move up a level and only the extra controls appear.

Every Essential Eight question is answered from the same live ISM release, so when ASD reworks a mitigation strategy your assessment picks it up on the next release check.

Maturity Level 146controls in the ML1 baseline
Maturity Level 287controls in the ML2 baseline
Maturity Level 3123controls in the ML3 baseline

Counts from ISM release v2026.09.4. They change as ASD publishes, and so does the Advisor.

Operational technology

Built for the plant floor, not just the data centre.

ICS, SCADA and building-management systems get assessed against the same ISM, but the context is different. The Advisor overlays IEC 62443, NIST SP 800-82, Purdue reference levels and the ASD Principles of Operational Technology Cyber Security on the ISM controls, so you can filter by Purdue level or 62443 requirement and see exactly which controls carry it.

IEC 62443

Filter ISM controls by the 62443 requirement they satisfy.

Purdue levels

Ask what applies at Level 2 versus Level 3.5 and get controls, not a diagram.

NIST SP 800-82

Cross-referenced to the US ICS guidance your vendors quote.

ASD OT principles

Mapped to the published Australian principles, with the applicability spelt out.

The difference

Assessment tooling, before and after.

The spreadsheet and a chatbot

  • Control text copied from last year’s PDF
  • AI answers from training data, ids invented
  • Unassessed rows quietly drop off the count
  • Re-keying the SSP annex by hand
  • Another SaaS tenancy holding your security posture
  • Per-seat pricing for every reviewer

Security Assessment Advisor

  • Quoted from the current published release, stamped on the answer
  • Every id verified against the live catalogue
  • Unassessed means gap. Always.
  • SSP annex, POA&M and reports generated from the conversation
  • Runs in your Azure tenancy, on your laptop, or with the network cable out
  • One licence per organisation, not per person

Hosted your way

Your AI. Your laptop, your server, or your cloud.

Your security posture is the most sensitive document you own, and it never touches a shared multi-tenant service. The Advisor runs on hardware you control, in whichever shape matches your accreditation boundary. Your house, your rules.

Your own Azure tenancy

One isolated instance per customer: your Azure resources, your Entra ID app, your container registry, your Copilot agent. Sign-in and authorisation enforced on every request. Nothing shared with us, or anyone else, at run time.

On the assessor’s laptop

Run it locally in VS Code or Claude Desktop. Nothing leaves the machine except the catalogue download, and exports land in the folder you ask for.

Air-gapped

A single container with both standards baked in. Delivered by file, verified by checksum, runs with no network at all. Built for the environments where “cloud” isn’t an option.

Pricing and plans

RRP pricing for every team size.

6–25 users
$80

per user / month

26–100 users
$60

per user / month

101+ users
Contact us

for volume pricing

Annual prepay saves 15%

Talk to us

Book a chat

See it run against your own SSP.

Bring a system you’re assessing right now. In 25 minutes we’ll connect the Advisor to Copilot or Claude, scope the system, and show you the first gap analysis. No slides.

Or email contactus@mojoup.com.au.