Restrict Microsoft Office macros
Microsoft Office macros are small programs embedded in documents and spreadsheets. They are also a favourite delivery mechanism for malware — a booby-trapped invoice or résumé that runs code the moment someone clicks "enable". This control restricts which macros can run, especially in files from the internet.
It is control 3 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Macro-based phishing remains a leading intrusion method against Australian businesses, so insurers often ask how macros are restricted. If your business does not use Microsoft Office, this control may not apply to you.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Are Office macros turned off for staff who don't have a genuine business need for them?
ACSC requirement: “Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.”
Are Office macros in files downloaded from the internet (including email attachments) blocked from running?
ACSC requirement: “Microsoft Office macros in files originating from the internet are blocked.”
Does your antivirus software scan Office macros?
ACSC requirement: “Microsoft Office macro antivirus scanning is enabled.”
Are staff prevented from changing macro security settings themselves?
ACSC requirement: “Microsoft Office macro security settings cannot be changed by users.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Are Office macros blocked from making low-level Windows system calls (Win32 API)?
ACSC requirement: “Microsoft Office macros are blocked from making Win32 API calls.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Can macros only run if they're digitally signed by a trusted publisher, stored in a Trusted Location, or sandboxed?
ACSC requirement: “Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).