Cyber Insurance Subjectivity Tracker

Controls / Application control and hardening

Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: extend application control to internet-facing servers, add the recommended blocklist, and review the rules each year.

In Australia

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1490
Essential Eight, Maturity Level Two

Application control is implemented on internet-facing servers. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1490 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Application control policy on internet-facing servers in enforcement mode; Server coverage report

ISM-1544
Essential Eight, Maturity Level Two

Microsoft’s recommended application blocklist is implemented. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1544 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for The vendor's recommended application blocklist deployed in the ruleset; Version date of the blocklist in use

ISM-1582
Essential Eight, Maturity Level Two

Application control rulesets are validated on an annual or more frequent basis. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1582 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Ruleset validation records at least annually with reviewer and changes; Removal of obsolete allow rules

ISM-1871
Essential Eight, Maturity Level Two

Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1871 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rules applying application control across all locations, not only user profiles and temporary folders; Test of execution from other writable locations

ISM-1660
Essential Eight, Maturity Level Two

Allowed and blocked application control events are centrally logged. Required at Maturity Levels Two and Three of the Application control mitigation strategy (Appendices B and C); ISM control ISM-1660 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Central logging of allowed and blocked application control events; Sample of blocked events from workstations and servers

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 2.5
CIS Controls v8.1
Allowlist Authorized Software

Apply technical measures, for instance application allowlisting, so that only authorised software is able to run or be opened. Reassess at least twice a year.

The requirement's own words: at least twice a year

evidence an assessor asks for Application allowlisting policy configuration, such as AppLocker or WDAC, showing enforcement mode; Blocked execution logs and records of the twice-yearly allowlist reassessment; Allowlist rule set export showing publisher, path or hash rules and who approved each addition; Endpoint policy assignment report showing allowlisting in enforce mode rather than audit-only across device groups; Minutes or ticket from the twice-yearly allowlist review listing rules added and removed

CIS 2.6
CIS Controls v8.1
Allowlist Authorized Libraries

Apply technical measures so that a system process can load only authorised software libraries (for example particular .dll, .ocx or .so files, among others), and stop unauthorised libraries from loading. Reassess at least twice a year.

The requirement's own words: at least twice a year

evidence an assessor asks for Library allowlisting configuration covering .dll, .ocx and .so files; Logs of blocked library loads and records of the twice-yearly reassessment; DLL rule collection or WDAC policy export showing library enforcement enabled, not just executable rules; Sample of blocked library load events with triage outcome for each; Approved library list with signing certificate or hash for each authorised module

PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.19
ISO/IEC 27001:2022 (lens)
Installation of software on operational systems

Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19.

evidence an assessor asks for Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule