Skip to content
arrow_back
search
ISM-1675 policy ASD Information Security Manual (ISM)

Prevent Enabling Untrusted Microsoft Office Macros

Macros from untrusted sources in Microsoft Office can't be enabled through standard interfaces.

record_voice_over

Plain language

This control is about stopping Microsoft Office from running suspicious little programs called macros that originate from sources we don't trust. It's important because if harmful macros get in, they can mess with your files or steal information, like leaving your front door open for thieves.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.
policy ASD Information Security Manual (ISM) ISM-1675
priority_high

Why it matters

If untrusted Office macros run, they can automate data theft or malware spread, critically compromising business operations and security.

settings

Operational notes

Regularly verify that macro settings are enforced to block unsigned macros and educate users to avoid altering these via Message Bar or Backstage View.

Mapping detail

Mapping

Direction

Controls