Skip to content
arrow_back
search
E8-AC-ML2.1 bolt ASD Essential Eight

Application control is implemented on internet-facing servers

Ensure only approved applications can run on servers accessible from the internet.

record_voice_over

Plain language

This control is about making sure that only software you have approved can run on servers that people outside your organisation can access via the internet. This matters because if random or harmful programs can run on these servers, it opens the door to cyber attackers who might steal information, cause disruption, or damage your reputation.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Application control is implemented on internet-facing servers.
bolt ASD Essential Eight E8-AC-ML2.1
priority_high

Why it matters

Without application control on internet-facing servers, attackers can run unauthorised executables or scripts, enabling initial access, web shell deployment and data exfiltration.

settings

Operational notes

Maintain a tested allowlist on each internet-facing server: review additions/changes after patching and deployments, and alert on any blocked execution attempts.

Mapping detail

Mapping

Direction

Controls