Skip to content
arrow_back
search
ISM-1582 policy ASD Information Security Manual (ISM)

Routine Validation of Application Control Rulesets

Check and update app control rules at least yearly to maintain security.

record_voice_over

Plain language

This control is about routinely checking and updating the rules that determine which applications can run on your organisation's computers. It's important because if these rules get outdated, it might let dangerous software slip through, putting your business at risk of cyber attacks.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Application control rulesets are validated on an annual or more frequent basis.
policy ASD Information Security Manual (ISM) ISM-1582
priority_high

Why it matters

Outdated application control rules can allow unapproved or malicious executables to run, increasing the risk of compromise and disruption.

settings

Operational notes

Validate application control rulesets at least annually and after major changes; remove stale allow rules, confirm blocks still work, and record results and exceptions.

Mapping detail

Mapping

Direction

Controls