Cyber Insurance Subjectivity Tracker

Controls / Application control and hardening

Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: turn on application control on workstations so only allowed programs, scripts and installers run.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-0843
Essential Eight, Maturity Level One

Application control is implemented on workstations. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-0843 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Application control policy deployed to all workstations with enforcement mode; Compliance report showing coverage

ISM-1657
Essential Eight, Maturity Level One

Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1657 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Approved set covering executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets; Test results for each file type

ISM-1870
Essential Eight, Maturity Level One

Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. Required at Maturity Levels One, Two and Three of the Application control mitigation strategy (Appendices A, B and C); ISM control ISM-1870 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rules preventing execution from user profiles and temporary folders used by the operating system, browsers and email clients; Test of an executable launched from a user profile folder

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 2.5
CIS Controls v8.1
Allowlist Authorized Software

Apply technical measures, for instance application allowlisting, so that only authorised software is able to run or be opened. Reassess at least twice a year.

The requirement's own words: at least twice a year

evidence an assessor asks for Application allowlisting policy configuration, such as AppLocker or WDAC, showing enforcement mode; Blocked execution logs and records of the twice-yearly allowlist reassessment; Allowlist rule set export showing publisher, path or hash rules and who approved each addition; Endpoint policy assignment report showing allowlisting in enforce mode rather than audit-only across device groups; Minutes or ticket from the twice-yearly allowlist review listing rules added and removed

CIS 2.7
CIS Controls v8.1
Allowlist Authorized Scripts

Apply technical measures, such as digital signing and version control, so that only authorised scripts (for example particular .ps1 or .py files, among others) can run, and stop unauthorised scripts from running. Reassess at least twice a year.

The requirement's own words: at least twice a year

evidence an assessor asks for Script control configuration requiring signing or version control for .ps1, .py and similar scripts; Logs of blocked unsigned scripts and records of the twice-yearly reassessment; Script execution policy and constrained language settings enforced centrally; Code signing certificate issuance records and the repository approval workflow for scripts; Sample of production scripts showing a valid signature or a commit in the controlled repository

PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-MP.4
Cyber Essentials
Application Allowlisting (Alternative)

Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained.

evidence an assessor asks for WDAC/AppLocker policy; allowlist register; exception process

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.19
ISO/IEC 27001:2022 (lens)
Installation of software on operational systems

Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19.

evidence an assessor asks for Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule