Skip to content
arrow_back
search
ISM-1668 policy ASD Information Security Manual (ISM)

Prevent Microsoft Office from Creating Executable Files

Microsoft Office is set to not produce executable files to enhance security.

record_voice_over

Plain language

Microsoft Office should not create executable files because these files can contain harmful software that may harm your computer or network. By preventing Office from creating such files, you reduce the risk of malicious software spreading and protect your organisation’s data and finances.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Microsoft Office is blocked from creating executable content.
policy ASD Information Security Manual (ISM) ISM-1668
priority_high

Why it matters

Allowing Office to create executable files can enable malware dropper behaviour, leading to compromise, data exfiltration and financial loss.

settings

Operational notes

Enforce Office policies that block executable creation; regularly verify settings via GPO/Intune and alert on changes to reduce malware dropped from Office.

Mapping detail

Mapping

Direction

Controls