Controls / Application control and hardening
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: harden office and PDF software and lock their security settings.
In Australia
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1412 Essential Eight, Maturity Level Two | Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1412 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Browser hardening baseline based on ASD and vendor guidance; Compliance report against the baseline |
| ISM-1542 Essential Eight, Maturity Level Two | Microsoft Office is configured to prevent activation of Object Linking and Embedding packages. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1542 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing activation of OLE packages in Office; Test with an embedded package |
| ISM-1667 Essential Eight, Maturity Level Two | Microsoft Office is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1667 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Attack surface reduction rule blocking Office from creating child processes in block mode; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1668 Essential Eight, Maturity Level Two | Microsoft Office is blocked from creating executable content. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1668 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rule blocking Office from creating executable content; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1669 Essential Eight, Maturity Level Two | Microsoft Office is blocked from injecting code into other processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1669 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Rule blocking Office from injecting code into other processes; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1670 Essential Eight, Maturity Level Two | PDF software is blocked from creating child processes. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1670 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Control blocking PDF software from creating child processes; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1823 Essential Eight, Maturity Level Two | Office productivity suite security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1823 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing users changing Office security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1824 Essential Eight, Maturity Level Two | PDF software security settings cannot be changed by users. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1824 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Policy preventing users changing PDF software security settings; Dated record of an assessor's attempt to defeat the setting, with the outcome |
| ISM-1859 Essential Eight, Maturity Level Two | Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1859 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Office hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host |
| ISM-1860 Essential Eight, Maturity Level Two | PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. Required at Maturity Levels Two and Three of the User application hardening mitigation strategy (Appendices B and C); ISM control ISM-1860 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for PDF software hardening baseline from ASD and vendor guidance; Endpoint management compliance report showing the setting applied on each in-scope host |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 2.2.1 PCI DSS v4.0.1 (add-on) | System configuration standards maintained Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts. evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 4.1 CIS Controls v8.1 | Establish and Maintain a Secure Configuration Process Set up and keep a process for configuring enterprise assets securely (end-user devices, portable and mobile ones included, IoT and other non-computing devices, and servers) as well as software (both operating systems and applications). Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Secure configuration process document covering end-user devices, network devices, IoT, servers and software; Secure configuration baselines the business has adopted, and the annual review record; Configuration standards per asset class, including IoT and mobile devices, with the deviations approved; Configuration compliance scan results against the approved baselines for a sample of assets; Evidence of the process reassessment after a major change such as a new OS release |
| PR.PS-01 NIST CSF 2.0 | Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Configuration management standards by platform; Hardening baselines and compliance reports; Configuration drift monitoring telemetry; Approved change management records; Configuration audit findings and remediation |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 2.2.1 PCI DSS v4.0.1 (add-on) | System configuration standards maintained Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts. evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.3 Cyber Essentials | Disable Auto-Run Features Disable auto-run or auto-play features that automatically execute code without user authorisation on removable media or network shares. evidence an assessor asks for AutoPlay disabled GPO export; Device management policy screenshot |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 2.2.1 PCI DSS v4.0.1 (add-on) | System configuration standards maintained Configuration standards must be developed, implemented and maintained so that they: (a) cover every system component; (b) address all known security vulnerabilities; (c) are consistent with vendor hardening recommendations or hardening standards the industry accepts; (d) are revised whenever new vulnerability issues come to light, following Requirement 6.3.1; and (e) are used whenever new systems are set up, and are confirmed to be in place before, or right after, a component goes live in a production environment. Applicability: no special notes; applies to every assessed entity. Objective under the customized approach: every system component is set up securely and consistently consistent with vendor guidance or hardening standards the industry accepts. evidence an assessor asks for Configuration standards for each component type (operating systems, databases, network devices, containers, cloud services) referencing CIS or vendor baselines; Change history of standards showing updates triggered by newly identified vulnerabilities; Build checklists or pipeline logs showing standards applied to new systems; Configuration compliance scan reports taken at or shortly after production deployment |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.9 ISO/IEC 27001:2022 (lens) | Configuration management The organization is to set, record, apply, watch and review how its hardware, software, services and networks are configured, security settings included. Purpose (stated in ISO/IEC 27002:2022): ensures systems and networks work correctly with required security settings and are not changed without approval or by mistake. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.9. evidence an assessor asks for Statement of Applicability entry for control A.8.9, showing inclusion or justified exclusion, implementation status and the risks it treats; Approved secure configuration templates or baselines for each platform, derived from vendor or independent guidance, with review dates; Configuration records or a CMDB showing owner, last change date, template version and relationships between assets; Change records showing configuration changes passed through change management; Configuration compliance scan results comparing actual settings with templates, and records of deviations corrected |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.