Skip to content
arrow_back
search
ISM-1656 policy ASD Information Security Manual (ISM)

Implement Application Control on Secure Servers

Ensure servers not connected to the internet have application control for security.

record_voice_over

Plain language

This control ensures that applications on servers not connected to the internet are managed carefully to prevent unauthorised programs from running, which could lead to data breaches or operational disruptions. This is important because if these unmanaged applications run unchecked, they could introduce malware or cause other security issues that are hard to detect and manage since the servers are isolated from the internet.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Application control is implemented on non-internet-facing servers.
policy ASD Information Security Manual (ISM) ISM-1656
priority_high

Why it matters

Uncontrolled applications on non-internet-facing servers can introduce malware, leading to data breaches and operational disruptions.

settings

Operational notes

Regularly audit application control allowlists on non-internet-facing servers; alert on blocked executions and investigate newly installed binaries.

Mapping detail

Mapping

Direction

Controls