Cyber Insurance Subjectivity Tracker

Controls / Application control and hardening

Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: harden office and PDF software and lock their security settings.

In Australia

Maturity Level Two

Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.

ClauseThe held text, and the evidence an assessor asks for
ISM-1412
Essential Eight, Maturity Level Two

Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1412 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Browser hardening baseline based on ASD and vendor guidance; Compliance report against the baseline

ISM-1542
Essential Eight, Maturity Level Two

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1542 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing activation of OLE packages in Office; Test with an embedded package

ISM-1667
Essential Eight, Maturity Level Two

Microsoft Office is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1667 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Attack surface reduction rule blocking Office from creating child processes in block mode; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1668
Essential Eight, Maturity Level Two

Microsoft Office is blocked from creating executable content. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1668 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rule blocking Office from creating executable content; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1669
Essential Eight, Maturity Level Two

Microsoft Office is blocked from injecting code into other processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1669 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Rule blocking Office from injecting code into other processes; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1670
Essential Eight, Maturity Level Two

PDF software is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1670 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Control blocking PDF software from creating child processes; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1823
Essential Eight, Maturity Level Two

Office productivity suite security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1823 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing users changing Office security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1824
Essential Eight, Maturity Level Two

PDF software security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1824 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Policy preventing users changing PDF software security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome

ISM-1859
Essential Eight, Maturity Level Two

Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1859 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for Office hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host

ISM-1860
Essential Eight, Maturity Level Two

PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1860 in ASD's Essential Eight to ISM mapping (December 2023).

evidence an assessor asks for PDF software hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 2.2.1
PCI DSS v4.0.1 (add-on)
System configuration standards maintained

Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts.

evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 4.1
CIS Controls v8.1
Establish and Maintain a Secure Configuration Process

Set up and keep a process for configuring enterprise assets securely (end-user devices, portable and mobile ones included, IoT and other non-computing devices, and servers) as well as software (both operating systems and applications). Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard.

evidence an assessor asks for Secure configuration process document covering end-user devices, network devices, IoT, servers and software; Secure configuration baselines the business has adopted, and the annual review record; Configuration standards per asset class, including IoT and mobile devices, with the deviations approved; Configuration compliance scan results against the approved baselines for a sample of assets; Evidence of the process reassessment after a major change such as a new OS release

PR.PS-01
NIST CSF 2.0

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 2.2.1
PCI DSS v4.0.1 (add-on)
System configuration standards maintained

Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts.

evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-SC.3
Cyber Essentials
Disable Auto-Run Features

Disable auto-run or auto-play features that automatically execute code without user authorisation on removable media or network shares.

evidence an assessor asks for AutoPlay disabled GPO export; Device management policy screenshot

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 2.2.1
PCI DSS v4.0.1 (add-on)
System configuration standards maintained

Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts.

evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.9
ISO/IEC 27001:2022 (lens)
Configuration management

The organization is to set, record, apply, watch and review how its hardware, software, services and networks are configured, security settings included. Purpose (stated in ISO/IEC 27002:2022): ensures systems and networks work correctly with required security settings and are not changed without approval or by mistake. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.9.

evidence an assessor asks for Statement of Applicability entry for control A.8.9, showing inclusion or justified exclusion, implementation status and the risks it treats; Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates; Configuration records or a CMDB showing owner, last change date, template version and relationships between assets; Change records showing configuration changes passed through change management; Configuration compliance scan results comparing actual settings with templates, and records of deviations corrected

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule