Skip to content
arrow_back
search
ISM-1542 policy ASD Information Security Manual (ISM)

Disable OLE in Microsoft Office for Security

Microsoft Office is set to block OLE, a feature that could pose security risks.

record_voice_over

Plain language

This control requires Microsoft Office to disable a feature called Object Linking and Embedding (OLE). OLE can create opportunities for cyber attackers to sneak harmful software into your system through supposedly legitimate files. By turning off OLE, you reduce the risk of opening your business up to data breaches or malware infections, which could cost you time, money, and trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.
policy ASD Information Security Manual (ISM) ISM-1542
priority_high

Why it matters

If OLE is not disabled, embedded OLE packages in Office files may execute, enabling malware infection, data theft, or host compromise.

settings

Operational notes

Regularly verify Office GPO/registry settings keep OLE activation disabled and test with sample files after updates to ensure it cannot be re-enabled.

Mapping detail

Mapping

Direction

Controls