Controls / Application control and hardening
Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: extend application control to internet-facing servers, add the recommended blocklist, and review the rules each year.
In Australia
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1490 Essential Eight, Maturity Level Two | Application control is implemented on internet-facing servers. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1490 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Application control policy on internet-facing servers in enforcement mode; Server coverage report |
| ISM-1544 Essential Eight, Maturity Level Two | Microsoft’s recommended application blocklist is implemented. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1544 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for The vendor's recommended application blocklist deployed in the ruleset; Version date of the blocklist in use |
| ISM-1582 Essential Eight, Maturity Level Two | Application control rulesets are validated on an annual or more frequent basis. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1582 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Ruleset validation records at least annually with reviewer and changes; Removal of obsolete allow rules |
| ISM-1871 Essential Eight, Maturity Level Two | Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1871 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rules applying application control across all locations, not only user profiles and temporary folders; Test of execution from other writable locations |
| ISM-1660 Essential Eight, Maturity Level Two | Allowed and blocked application control events are centrally logged. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1660 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Central logging of allowed and blocked application control events; Sample of blocked events from workstations and servers |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 2.5 CIS Controls v8.1 | Allowlist Authorized Software Apply technical measures, for instance application allowlisting, so that only authorised software is able to run or be opened. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Application allowlisting policy configuration, such as AppLocker or WDAC, showing enforcement mode; Blocked execution logs and records of the twice-yearly allowlist reassessment; Allowlist rule set export showing publisher, path or hash rules and who approved each addition; Endpoint policy assignment report showing allowlisting in enforce mode rather than audit-only across device groups; Minutes or ticket from the twice-yearly allowlist review listing rules added and removed |
| CIS 2.6 CIS Controls v8.1 | Allowlist Authorized Libraries Apply technical measures so that a system process can load only authorised software libraries (for example particular .dll, .ocx or .so files, among others), and stop unauthorised libraries from loading. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Library allowlisting configuration covering .dll, .ocx and .so files; Logs of blocked library loads and records of the twice-yearly reassessment; DLL rule collection or WDAC policy export showing library enforcement enabled, not just executable rules; Sample of blocked library load events with triage outcome for each; Approved library list with signing certificate or hash for each authorised module |
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.19 ISO/IEC 27001:2022 (lens) | Installation of software on operational systems Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19. evidence an assessor asks for Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.