Skip to content
arrow_back
search
ISM-1489 policy ASD Information Security Manual (ISM)

Prevent Users from Changing Office Macro Security Settings

Users cannot alter the security settings for Microsoft Office macros, ensuring consistent protection.

record_voice_over

Plain language

This control makes sure that users in your organisation can't change the security settings related to Microsoft Office macros. It's important because if someone accidentally changes these settings, malicious code hidden in office documents could run unchecked, potentially causing data breaches or other security incidents.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Microsoft Office macro security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1489
priority_high

Why it matters

If users change Office macro settings, malicious macros may run, causing data breaches or ransomware.

settings

Operational notes

Regularly confirm GPO enforces Office macro security settings, and monitor/resolve any user attempts to bypass the lock-down.

Mapping detail

Mapping

Direction

Controls