Skip to content

Application control

Application control means your computers only run software the business has approved. Most security tools try to catch bad software. This one works the other way round: if a program is not on the approved list, it does not run. It is one of the most effective defences against ransomware and malicious downloads.

It is control 1 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.

Why this Essential 8 control comes up with insurers

It blocks unapproved programs outright, so at the higher maturity levels insurers commonly read application control as a strong sign of a hardened environment.

Maturity Level 1: the baseline

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Do staff computers only allow approved programs to run (application control / allow-listing)?

    ACSC requirement: “Application control is implemented on workstations.”

  • Does that control cover all executable file types (programs, scripts, installers and similar), limiting them to an approved set?

    ACSC requirement: “Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.”

Maturity Level 2: the common target

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Is Microsoft's recommended application blocklist applied, blocking known-risky tools?

    ACSC requirement: “Microsoft's recommended application blocklist is implemented.”

  • Are your application control rules reviewed at least once a year?

    ACSC requirement: “Application control rulesets are validated on an annual or more frequent basis.”

Maturity Level 3: advanced

Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:

  • Is Microsoft's vulnerable driver blocklist applied?

    ACSC requirement: “Microsoft's vulnerable driver blocklist is implemented.”

These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).