Controls / Application control and hardening
Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: block macros in office files from the internet, switch them off for staff who do not need them, and lock the setting.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1488 Essential Eight, Maturity Level One | Microsoft Office macros in files originating from the internet are blocked. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1488 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy blocking macros in files from the internet (mark of the web); Test with a downloaded macro-enabled file |
| ISM-1489 Essential Eight, Maturity Level One | Microsoft Office macro security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1489 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy locking macro security settings so users cannot change them; Screenshot of greyed-out Trust Center settings |
| ISM-1671 Essential Eight, Maturity Level One | Microsoft Office macros are disabled for users that do not have a demonstrated business requirement. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1671 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Group policy disabling macros for users without a demonstrated business requirement; Register of users approved for macros with justification |
| ISM-1672 Essential Eight, Maturity Level One | Microsoft Office macro antivirus scanning is enabled. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1672 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Configuration enabling macro antivirus scanning (AMSI integration); Test with a benign detection sample |
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1673 Essential Eight, Maturity Level Two | Microsoft Office macros are blocked from making Win32 API calls. Required at Maturity Levels Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices B and C); ISM control ISM-1673 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Attack surface reduction rule blocking Win32 API calls from Office macros in block mode; Rule compliance report |
In the United States
No requirement in the core list for the United States covers this control; it is on the schedule as a condition beyond the core list.
In United Kingdom
No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.7 ISO/IEC 27001:2022 (lens) | Protection against malware Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7. evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.