Restrict User Application Extensions
Limit application extensions to those approved by the organisation.
Plain language
This security measure ensures that employees can only install app extensions that your organisation has approved. This is important because unauthorised extensions can create security vulnerabilities, allowing viruses or hackers access to your systems.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
User Application HardeningOfficial control statement
Extensions for user applications are restricted to an organisation-approved set.
Why it matters
Without this control, harmful software could sneak in through unapproved extensions, risking data breaches or system downtime.
Operational notes
Regular updates to the approved extensions list and routine monitoring help ensure compliance and security integrity.
Implementation tips
- IT team should create a list of approved extensions: Start by gathering input from department heads to understand what extensions are necessary for their teams. Regularly update this list to meet changing needs.
- System administrators should configure application settings: Adjust settings in your software management tools to block all extensions except the ones on the approved list. Use guides from your software vendors for specific steps.
- Managers should communicate policies to staff: Explain the importance of the policy and provide training on how to request new extensions. Ensure staff understand the security risks associated with unauthorised extensions.
- Look atany installation attempts of non-approved extensions and take corrective actions
- Procurement staff should review and approve new extensions: Employees can request new extensions by submitting a form that includes justification. Ensure all new extension requests are reviewed for security impact before approval.
Audit / evidence tips
- Askthe approved extensions list: Request the current list that outlines all extensions approved for useLook atdate stamps and revision historyGoodA complete, up-to-date list reviewed regularly
- Askto see application configuration settings: Request documentation of how extensions are restrictedLook atsettings that prevent installation of non-approved extensionsGoodSettings that block all non-approved extensions
- Askcommunication records about the policy: Request materials or announcements sent to employees about extension restrictionsLook atclear instructions and rationale provided to staffGoodWell-documented guidance and training evidence
- Askmonitoring logs: Request records of monitoring activities related to extension installationsLook atevidence of regular checks and responses to unauthorised activityGoodLogs showing proactive monitoring and incident management
- Askextension request forms: Review forms submitted by employees for new extensionsLook atjustifications and approval signaturesGoodForms with thorough justifications and a clear approval process
Cross-framework mappings
How ISM-1235 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(4)expand_less | ||
handshakeSupports(1)expand_less | ||
linkRelated(1)expand_less | ||
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.