Skip to content
arrow_back
search
ISM-1659 policy ASD Information Security Manual (ISM)

Implement Microsoft's Vulnerable Driver Blocklist

Use Microsoft's list to stop harmful drivers from running on systems.

record_voice_over

Plain language

Microsoft's vulnerable driver blocklist is a tool that helps stop problematic software drivers from running on your computer systems. If these drivers aren't blocked, they can let viruses or hackers into your system, potentially causing personal data theft, financial loss, or business disruption.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Microsoft's vulnerable driver blocklist is implemented.
policy ASD Information Security Manual (ISM) ISM-1659
priority_high

Why it matters

Unblocked vulnerable Windows drivers can be abused to gain kernel access, bypass EDR, and cause data breaches or outages.

settings

Operational notes

Keep Microsoft's vulnerable driver blocklist enabled, update it via Windows updates, and validate blocked driver events in logs/EDR.

Mapping detail

Mapping

Direction

Controls