Skip to content
arrow_back
search
ISM-1672 policy ASD Information Security Manual (ISM)

Enable Antivirus Scanning for Office Macros

Ensure Microsoft Office is set to scan macros for viruses to protect against malware.

record_voice_over

Plain language

Having Microsoft Office scan macros for viruses is crucial because macros can be used by hackers to sneak viruses into your computer. If this isn't done, these hidden viruses could steal important information or cause serious disruption to your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Microsoft Office macro antivirus scanning is enabled.
policy ASD Information Security Manual (ISM) ISM-1672
priority_high

Why it matters

If Office macros aren’t scanned for viruses, macro malware can execute, causing credential theft, data loss or disruption.

settings

Operational notes

Confirm Office macro antivirus scanning is enabled in AV/EDR policy; test with a macro sample and monitor detections.

Mapping detail

Mapping

Direction

Controls