Annual Validation of Application Control Rulesets
Check and approve application control rules once a year to ensure they are effective.
Plain language
Application control rules are like the doormen for your computer systems. Checking these rules every year is important because if the wrong programs get in, your data could be at risk, which might lead to financial loss or damage to your reputation.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
ML2, ML3
Official control statement
Application control rulesets are validated at least annually.
Why it matters
Neglected application rules can allow harmful software to run, exposing the organisation to data breaches or operational downtime.
Operational notes
Ensure application reviews are completed annually and are a collaborative effort. Keep a clear record of any changes for quick reference during audits.
Implementation tips
- The IT manager should schedule an annual review of application control rulesets. This involves setting a date each year to go over the list of approved applications and make sure it's up to date.
- IT staff should create a list of all current applications running on the system. They can do this by checking software installation logs and comparing them with the approved list.
- System owners should work with IT staff to identify any applications that are no longer needed. They can use these findings to remove unnecessary or unauthorized applications from systems.
- Managers should involve users in the process to confirm that only required applications are installed. This can be done by sending a short survey asking about application usage.
- The IT department should document any changes to application controls and store these for future audits. This includes noting why applications were removed or added and who made these decisions.
Audit / evidence tips
- Askthe list of current approved applications: Check if there's a formal, updated document listing all allowed softwareLook atrecent updates and approvalsGooda regularly updated list with dates and approvals
- Look atrecords of any additions or removals from the list. Check for authorisation signatures and justificationsGooda clear log showing who approved changes and why
- Askto see the annual review meeting recordsLook atmeeting notes or minutes from these sessions. Verify discussions about the necessity and use of applicationsGoodnotes detailing decisions and attendance
- Look atinput from staff about applications used dailyGooddocumented user confirmations or concerns about application usage
- Aska demonstration of the application removal process: Watch how unused or misaligned applications are identified and removedLook ata smooth, clear processGooddemonstration shows effective removal without business disruption
Cross-framework mappings
How ISM-1582 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
E8
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| E8-RM-ML3.6 | E8-RM-ML3.6 requires an annual validation of Microsoft Office’s trusted publishers list to ensure only approved macro signers remain trusted | |
linkRelated(1)expand_less | ||
| E8-AC-ML2.4 | ISM-1582 requires application control rulesets to be validated on an annual or more frequent basis | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.