Skip to content
arrow_back
search
E8-AC-ML2.4 bolt ASD Essential Eight

Annual validation of application control rulesets

Check once a year or more that rules for allowing or blocking software are accurate.

record_voice_over

Plain language

Once a year or more often, it's essential to check that the rules for which software can run on your organisation's computers are still correct. This is important because if you don't, malicious or unapproved software could run and cause significant harm, like stealing sensitive information or damaging files.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Application control rulesets are validated on an annual or more frequent basis.
bolt ASD Essential Eight E8-AC-ML2.4
priority_high

Why it matters

If application control rulesets aren’t validated at least annually, outdated allow rules may permit malicious executables, enabling compromise, data theft or system damage.

settings

Operational notes

Validate application control rulesets at least annually: review allow/deny rules, remove obsolete entries, confirm business apps still function, and update rules to reflect current software and threats.

Mapping detail

Mapping

Direction

Controls