Skip to content
arrow_back
search
ISM-1487 policy ASD Information Security Manual (ISM)

Restrict Macro Editing to Privileged Users

Only authorised users can edit trusted Microsoft Office macros to prevent malicious code.

record_voice_over

Plain language

This control ensures that only certain people in your organisation can edit Microsoft Office macros, which are small programs used within documents. It's important because if the wrong person edits these macros, they could introduce harmful code that compromises your data or systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.
policy ASD Information Security Manual (ISM) ISM-1487
priority_high

Why it matters

If non-privileged users can edit macros in Office Trusted Locations, malicious code may be introduced, enabling compromise and data loss.

settings

Operational notes

Regularly audit privileged access so only authorised users can write or modify Office macros and content in Trusted Locations.

Mapping detail

Mapping

Direction

Controls