Skip to content
arrow_back
search
ISM-1674 policy ASD Information Security Manual (ISM)

Ensuring Secure Execution of Microsoft Office Macros

Only safe Microsoft Office macros are allowed to run, using security measures like sandboxing or trusted signatures.

record_voice_over

Plain language

This control is about making sure that only safe macros—small programs you can run in Microsoft Office—are allowed to execute on your computer. Without this, you could accidentally run a harmful macro that steals information, corrupts files, or damages your system.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.
policy ASD Information Security Manual (ISM) ISM-1674
priority_high

Why it matters

Unchecked Office macros can run malicious code, leading to compromise unless sandboxed, trusted or signed.

settings

Operational notes

Allow macro execution only from Trusted Locations, a sandbox, or macros signed by trusted publishers; review regularly.

Mapping detail

Mapping

Direction

Controls