Controls / Application control and hardening
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: harden web browsers: no internet ads or plug-in code from the internet, settings locked, the old built-in browser removed.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1485 Essential Eight, Maturity Level One | Web browsers do not process web advertisements from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1485 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser or network control blocking web advertisements from the internet; Configuration export |
| ISM-1486 Essential Eight, Maturity Level One | Web browsers do not process Java from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1486 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser policy blocking the plug-in code the requirement names from the internet; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1585 Essential Eight, Maturity Level One | Web browser security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1585 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy locking browser security settings; User test showing settings cannot be changed |
| ISM-1654 Essential Eight, Maturity Level One | Internet Explorer 11 is disabled or removed. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1654 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Evidence the retired built-in browser the requirement names is disabled or removed across hosts; Endpoint management compliance report showing the setting applied on each in-scope host |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 9.4 CIS Controls v8.1 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions Uninstall or disable any browser or email client plugin, extension or add-on application that is unauthorised or not needed. evidence an assessor asks for Browser and email client extension allowlist policy; Endpoint report of installed extensions with unauthorised ones removed; Browser and email add-in standard defining the approval route for new extensions; Managed browser policy and Outlook add-in configuration enforcing the allowlist; Periodic extension inventory report with removals of unapproved add-ons recorded |
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.1 Cyber Essentials | Remove or Disable Unused Software Remove or disable unnecessary user accounts, software, and services on devices to reduce the attack surface. evidence an assessor asks for gold image documentation; installed software inventory; disabled services list |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.23 ISO/IEC 27001:2022 (lens) | Web filtering The organization is to manage which external websites can be reached, so that exposure to malicious content falls. Purpose (stated in ISO/IEC 27002:2022): keeps malware off systems and blocks unauthorized web resources. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.23. evidence an assessor asks for Statement of Applicability entry for control A.8.23, showing inclusion or justified exclusion, implementation status and the risks it treats; Current rules on safe, proper use of online resources; Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites; Integration of threat intelligence feeds into block lists; The exception request and approval process with records of approved exceptions |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.