Skip to content
arrow_back
ISM-1657policyASD Information Security Manual (ISM)

Restrict Application Execution to Approved Set

Only approved software and scripts can run, enhancing system security.

record_voice_over

Plain language

This control ensures that only approved software is allowed to run on your organisation's computers. It's important because if unauthorised programs are executed, they could introduce viruses or allow hackers to steal information, causing serious business disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2025

Control Stack last updated

18 June 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.
policyASD Information Security Manual (ISM)ISM-1657
priority_high

Why it matters

Without application control (approved allow list), unauthorised executables, scripts or libraries can run, enabling malware, privilege abuse and unauthorised access to systems and data.

settings

Operational notes

Maintain and review the application allow list; test and deploy updates promptly. Verify enforcement blocks unapproved executables, scripts, installers and libraries, and monitor logs for blocked attempts.

build

Implementation tips

  • IT team: Compile a list of approved applications that are necessary for organisational tasks. Work with department heads to determine which programs are essential for daily operations and ensure these are the only ones allowed to run.
  • System owner: Implement application control software to manage which applications can be executed. Use the approved applications list to configure the software to block anything not listed.
  • Management: Communicate to all staff the importance of using only approved software for their tasks. This can be done via email or a team meeting, highlighting the risks of unauthorised software.
  • IT team: Regularly review and update the list of approved applications. Set a quarterly meeting with key stakeholders to ensure new software needs are considered and keep the list current.
  • IT team: Train staff on recognising and reporting attempts to run unauthorised software. Offer workshops or online courses explaining the steps they should take if they receive suspicious software requests.
fact_check

Audit / evidence tips

  • AskA copy of the approved applications list: Request the list of software and scripts that are currently approved for useGoodList will have software names, version numbers, and approval dates
  • AskA demonstration of the application control software: Request a live demonstration showing how the software blocks unauthorised applicationsGoodDemonstration will show blocked attempts to run unapproved applications
  • AskResults of the latest review of approved applications: Request documentation of the last review meeting outcomesGoodIncludes a summary of reviewed applications and any changes made
  • AskTo see staff training records on application control: Request evidence of completed training courses or sessions
  • AskExamples of user reports on unauthorised software attemptsGoodShows that staff are vigilant and reports are being addressed promptly
link

Cross-framework mappings

How ISM-1657 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 8.18Annex A 8.18 requires restricting and tightly controlling use of utility programs that can override system and application controls, effe...

E8

ControlNotesDetails
layersPartially meets(3)expand_less
sync_altPartially overlaps(1)expand_less
handshakeSupports(3)expand_less
linkRelated(2)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls