Cyber Insurance Subjectivity Tracker

Controls / Application control and hardening

Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: block macros in office files from the internet, switch them off for staff who do not need them, and lock the setting.

In Australia

Maturity Level One

ClauseThe held text, and the evidence an assessor asks for
ISM-1488
Essential Eight, Maturity Level One

Microsoft Office macros in files originating from the internet are blocked. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1488 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy blocking macros in files from the internet (mark of the web); Test with a downloaded macro-enabled file

ISM-1489
Essential Eight, Maturity Level One

Microsoft Office macro security settings cannot be changed by users. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1489 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy locking macro security settings so users cannot change them; Screenshot of greyed-out Trust Center settings

ISM-1671
Essential Eight, Maturity Level One

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1671 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Group policy disabling macros for users without a demonstrated business requirement; Register of users approved for macros with justification

ISM-1672
Essential Eight, Maturity Level One

Microsoft Office macro antivirus scanning is enabled. Required at Maturity Levels One, Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices A, B and C); ISM control ISM-1672 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Configuration enabling macro antivirus scanning (AMSI integration); Test with a benign detection sample

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1673
Essential Eight, Maturity Level Two

Microsoft Office macros are blocked from making Win32 API calls. Required at Maturity Levels Two and Three of the Restrict Microsoft Office macros mitigation strategy (Appendices B and C); ISM control ISM-1673 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Attack surface reduction rule blocking Win32 API calls from Office macros in block mode; Rule compliance report

In the United States

No requirement in the core list for the United States covers this control; it is on the schedule as a condition beyond the core list.

In United Kingdom

No requirement in the core list for the United Kingdom covers this control; it is on the schedule as a condition beyond the core list.

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.7
ISO/IEC 27001:2022 (lens)
Protection against malware

Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7.

evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule