User application hardening
User application hardening means switching off the risky features of everyday software that attackers abuse — browsers running Java or ads from the internet, Office spawning other programs, legacy tools like Internet Explorer 11. Most businesses never need these features, so turning them off costs little and removes real attack paths.
It is control 4 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Hardening reduces the "drive-by" attack surface a business exposes just by browsing and reading email — a category insurers pay attention to because it needs no mistake from staff to be exploited.
Maturity Level 1 — the baseline
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is Internet Explorer 11 disabled or removed from your computers? (If you have no Windows computers, answer Yes.)
ACSC requirement: “Internet Explorer 11 is disabled or removed.”
Are your web browsers set so they don't run Java content from the internet?
ACSC requirement: “Web browsers do not process Java from the internet.”
Do your browsers block web advertisements (for example via a managed ad-blocker)?
ACSC requirement: “Web browsers do not process web advertisements from the internet.”
Are staff prevented from changing browser security settings?
ACSC requirement: “Web browser security settings cannot be changed by users.”
Maturity Level 2 — the common target
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is Microsoft Office blocked from launching other programs (child processes)?
ACSC requirement: “Microsoft Office is blocked from creating child processes.”
Is PowerShell activity on your Windows computers recorded in a central log? (If you have no Windows computers, answer Yes.)
ACSC requirement: “PowerShell module logging, script block logging and transcription events are centrally logged.”
Maturity Level 3 — advanced
Questions worth asking yourself, with the underlying ACSC requirement (November 2023 model) each one reflects:
Is PowerShell restricted to Constrained Language Mode? (If you have no Windows computers, answer Yes.)
ACSC requirement: “PowerShell is configured to use Constrained Language Mode.”
These are the criteria assessed by our free self-assessment — a representative subset of the full ACSC model, which contains further requirements at each level. The full model is published at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).