Skip to content
arrow_back
ISM-1235policyASD Information Security Manual (ISM)

Restrict User Application Extensions

Limit application extensions to those approved by the organisation.

record_voice_over

Plain language

This security measure ensures that employees can only install app extensions that your organisation has approved. This is important because unauthorised extensions can create security vulnerabilities, allowing viruses or hackers access to your systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Extensions for user applications are restricted to an organisation-approved set.
policyASD Information Security Manual (ISM)ISM-1235
priority_high

Why it matters

Without this control, harmful software could sneak in through unapproved extensions, risking data breaches or system downtime.

settings

Operational notes

Regular updates to the approved extensions list and routine monitoring help ensure compliance and security integrity.

build

Implementation tips

  • IT team should create a list of approved extensions: Start by gathering input from department heads to understand what extensions are necessary for their teams. Regularly update this list to meet changing needs.
  • System administrators should configure application settings: Adjust settings in your software management tools to block all extensions except the ones on the approved list. Use guides from your software vendors for specific steps.
  • Managers should communicate policies to staff: Explain the importance of the policy and provide training on how to request new extensions. Ensure staff understand the security risks associated with unauthorised extensions.
  • Look atany installation attempts of non-approved extensions and take corrective actions
  • Procurement staff should review and approve new extensions: Employees can request new extensions by submitting a form that includes justification. Ensure all new extension requests are reviewed for security impact before approval.
fact_check

Audit / evidence tips

  • Askthe approved extensions list: Request the current list that outlines all extensions approved for useLook atdate stamps and revision historyGoodA complete, up-to-date list reviewed regularly
  • Askto see application configuration settings: Request documentation of how extensions are restrictedLook atsettings that prevent installation of non-approved extensionsGoodSettings that block all non-approved extensions
  • Askcommunication records about the policy: Request materials or announcements sent to employees about extension restrictionsLook atclear instructions and rationale provided to staffGoodWell-documented guidance and training evidence
  • Askmonitoring logs: Request records of monitoring activities related to extension installationsLook atevidence of regular checks and responses to unauthorised activityGoodLogs showing proactive monitoring and incident management
  • Askextension request forms: Review forms submitted by employees for new extensionsLook atjustifications and approval signaturesGoodForms with thorough justifications and a clear approval process
link

Cross-framework mappings

How ISM-1235 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
sync_altPartially overlaps(4)expand_less
handshakeSupports(1)expand_less
linkRelated(1)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls