Cyber Insurance Subjectivity Tracker

Controls / Application control and hardening

Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: harden web browsers: no internet ads or plug-in code from the internet, settings locked, the old built-in browser removed.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1485
Essential Eight, Maturity Level One

Web browsers do not process web advertisements from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1485 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser or network control blocking web advertisements from the internet; Configuration export

ISM-1486
Essential Eight, Maturity Level One

Web browsers do not process Java from the internet. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1486 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser policy blocking the plug-in code the requirement names from the internet; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1585
Essential Eight, Maturity Level One

Web browser security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1585 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy locking browser security settings; User test showing settings cannot be changed

ISM-1654
Essential Eight, Maturity Level One

Internet Explorer 11 is disabled or removed. Required at Maturity Levels One, Two and Three of the User application hardening mitigation strategy (Appendices A, B and C); ISM control ISM-1654 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Evidence the retired built-in browser the requirement names is disabled or removed across hosts; Endpoint management compliance report showing the setting applied on each in-scope host

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 9.4
CIS Controls v8.1
Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

Uninstall or disable any browser or email client plugin, extension or add-on application that is unauthorised or not needed.

evidence an assessor asks for Browser and email client extension allowlist policy; Endpoint report of installed extensions with unauthorised ones removed; Browser and email add-in standard defining the approval route for new extensions; Managed browser policy and Outlook add-in configuration enforcing the allowlist; Periodic extension inventory report with removals of unapproved add-ons recorded

PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-SC.1
Cyber Essentials
Remove or Disable Unused Software

Remove or disable unnecessary user accounts, software, and services on devices to reduce the attack surface.

evidence an assessor asks for gold image documentation; installed software inventory; disabled services list

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.23
ISO/IEC 27001:2022 (lens)
Web filtering

The organization is to manage which external websites can be reached, so that exposure to malicious content falls. Purpose (stated in ISO/IEC 27002:2022): keeps malware off systems and blocks unauthorized web resources. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.23.

evidence an assessor asks for Statement of Applicability entry for control A.8.23, showing inclusion or justified exclusion, implementation status and the risks it treats; Current rules on safe, proper use of online resources; Web filtering or secure web gateway configuration showing blocked categories such as malicious, phishing, command and control, illegal content and upload sites; Integration of threat intelligence feeds into block lists; The exception request and approval process with records of approved exceptions

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule