Skip to content
arrow_back
E8-AH-ML1.2boltASD Essential Eight

Web browsers must not execute Java content from the internet

Ensure web browsers block Java content from the internet to reduce security risks.

record_voice_over

Plain language

This control is about making sure your web browser doesn't run Java content from the internet, which can be a security risk. If Java content is allowed to run, it could be used by hackers to harm your computer or steal your information. It's like cutting off a potential way for crooks to break into your digital space.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML1

Official control statement

Web browsers do not process Java from the internet.
boltASD Essential EightE8-AH-ML1.2
priority_high

Why it matters

Allowing Java in web browsers can lead to serious breaches, as attackers exploit it for drive-by downloads and remote code execution.

settings

Operational notes

Regularly audit browser and plugin settings to ensure Java is blocked for internet content, as updates or user changes can re-enable it.

build

Implementation tips

  • IT team should review all web browsers used in the organisation to ensure they don't run Java content by changing browser settings or installing appropriate security add-ons.
  • System administrators should disable or remove Java plug-ins from web browsers to prevent Java content from running. This can be done through the browser's settings or group policies.
  • Security personnel should use web content filters to block Java content from websites accessed through the internet. This involves setting up rules that prevent Java from being downloaded or executed.
  • Office managers should communicate with employees about why Java is disabled on web browsers and the importance of not enabling it. This can be part of a regular security briefing.
fact_check

Audit / evidence tips

  • AskWhat steps have been taken to ensure web browsers do not run Java content?
  • GoodThere are group policy settings that clearly show Java is disabled across all browsers, and there is documentation or evidence of regular checks being conducted
  • AskWhich add-ons or extensions are installed on web browsers that relate to Java?
  • GoodNo active Java-related extensions are found, or they are clearly marked as disabled
  • AskHow are employees made aware of the policy regarding Java content?
  • GoodDocumented employee communications with clear guidelines against enabling Java in browsers, reinforced by security briefings
link

Cross-framework mappings

How E8-AH-ML1.2 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
linkRelated(1)expand_less
Annex A 8.23E8-AH-ML1.2 requires that web browsers do not process Java content from the internet to reduce exposure to exploitation via browser-borne...

ASD ISM

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
ISM-0963ISM-0963 requires organisations to implement web content filtering to block potentially harmful web-based content
ISM-1485E8-AH-ML1.2 requires that web browsers do not process Java content from the internet to reduce the attack surface from active content exe...
handshakeSupports(3)expand_less
ISM-0260E8-AH-ML1.2 requires that web browsers do not process Java content from the internet
ISM-0958E8-AH-ML1.2 requires that web browsers do not process Java content from the internet
ISM-1585E8-AH-ML1.2 requires that web browsers do not process Java content from the internet
linkRelated(3)expand_less
ISM-0961E8-AH-ML1.2 requires that web browsers do not process Java content from the internet
ISM-1486E8-AH-ML1.2 requires that web browsers do not process Java content sourced from the internet
ISM-2110ISM-2110 requires user applications to be hardened using ASD and vendor guidance, choosing the most restrictive settings when guidance co...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all User application hardening controls, or browse the full Essential Eight mitigation strategies library.

Mapping detail

Mapping

Direction

Controls