Skip to content
arrow_back
search
ISM-1671 policy ASD Information Security Manual (ISM)

Disabling Microsoft Office Macros for Unauthorised Users

Microsoft Office macros are turned off unless users have a proven need for them.

record_voice_over

Plain language

This control is about turning off Microsoft Office macros for anyone who doesn't have a clear business need to use them. Macros can be a back door for hackers to sneak into your systems if accessed by the wrong people, leading to data theft or malware attacks.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
policy ASD Information Security Manual (ISM) ISM-1671
priority_high

Why it matters

If Microsoft Office macros are enabled for users without a business need, macro malware is more likely to execute and compromise systems.

settings

Operational notes

Review and revalidate macro approvals regularly, limiting macro enablement to named users with a current, documented business requirement.

Mapping detail

Mapping

Direction

Controls