Skip to content
arrow_back
search
ISM-1490 policy ASD Information Security Manual (ISM)

Implement Application Control on Internet-Facing Servers

Ensure application security by using controls on servers exposed to the internet.

record_voice_over

Plain language

This control is about making sure that only safe and approved applications can run on servers that can be accessed from the internet. It matters because if unsafe software gets onto these servers, hackers could exploit it to steal data, damage your systems, or disrupt your services.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Application control is implemented on internet-facing servers.
policy ASD Information Security Manual (ISM) ISM-1490
priority_high

Why it matters

Without application control on internet-facing servers, unauthorised binaries and scripts can execute, enabling compromise, data exfiltration, or service disruption.

settings

Operational notes

Maintain enforced allowlists on internet-facing servers; review and approve new binaries, test rules after patching, and monitor application-control logs for blocked or unexpected executions.

Mapping detail

Mapping

Direction

Controls