Skip to content
arrow_back
search
E8-AC-ML3.1 bolt ASD Essential Eight

Application control is implemented on non-internet-facing servers

Ensure only approved software can run on internal servers.

record_voice_over

Plain language

This control ensures that only software approved by your organisation can run on internal servers that do not face the internet. It matters because unauthorised or harmful software on these servers can lead to data theft, disruptions, or security breaches. Controlling what runs on these servers protects sensitive information and keeps systems secure.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Application control is implemented on non-internet-facing servers.
bolt ASD Essential Eight E8-AC-ML3.1
priority_high

Why it matters

Without application control, unauthorised software on internal servers can lead to data leaks and compromise critical business operations.

settings

Operational notes

Maintain an allow-list for non-internet-facing servers, review it regularly, and alert on any execution outside approved applications.

Mapping detail

Mapping

Direction

Controls