Application control
Application control means your computers only run software the business has approved. Instead of trying to spot every piece of malware, it flips the model: nothing runs unless it is on the allowed list. It is one of the most effective defences against ransomware and malicious downloads.
It is control 1 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Because it blocks unapproved programs outright, insurers commonly view application control as a strong signal of a hardened environment at higher maturity levels.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Do staff computers only allow approved programs to run (application control / allow-listing)?
ACSC requirement: “Application control is implemented on workstations.”
Does that control cover all executable file types — programs, scripts, installers and similar — limiting them to an approved set?
ACSC requirement: “Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is Microsoft's recommended application blocklist applied, blocking known-risky tools?
ACSC requirement: “Microsoft's recommended application blocklist is implemented.”
Are your application control rules reviewed at least once a year?
ACSC requirement: “Application control rulesets are validated on an annual or more frequent basis.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is Microsoft's vulnerable driver blocklist applied?
ACSC requirement: “Microsoft's vulnerable driver blocklist is implemented.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).