Skip to content
arrow_back
search
E8-AH-ML1.2 bolt ASD Essential Eight

Web browsers must not execute Java content from the internet

Ensure web browsers block Java content from the internet to reduce security risks.

record_voice_over

Plain language

This control is about making sure your web browser doesn't run Java content from the internet, which can be a security risk. If Java content is allowed to run, it could be used by hackers to harm your computer or steal your information. It's like cutting off a potential way for crooks to break into your digital space.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Web browsers do not process Java from the internet.
bolt ASD Essential Eight E8-AH-ML1.2
priority_high

Why it matters

Allowing Java in web browsers can lead to serious breaches, as attackers exploit it for drive-by downloads and remote code execution.

settings

Operational notes

Regularly audit browser and plugin settings to ensure Java is blocked for internet content, as updates or user changes can re-enable it.

Mapping detail

Mapping

Direction

Controls