Skip to content
arrow_back
search
ISM-1676 policy ASD Information Security Manual (ISM)

Validate Trusted Publishers for Microsoft Office

Ensure the list of trusted Microsoft Office publishers is checked at least once a year.

record_voice_over

Plain language

This control is about making sure that only trustworthy software companies can create or update documents in Microsoft Office on your computer. If you don't check these trusted companies regularly, someone sneaky could slide in harmful software, leading to loss of sensitive information or disruption of your daily operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Microsoft Office's list of trusted publishers is validated on an annual or more frequent basis.
policy ASD Information Security Manual (ISM) ISM-1676
priority_high

Why it matters

Unchecked Microsoft Office trusted publishers can allow malicious signed macros/add-ins to run, risking data compromise and disruption.

settings

Operational notes

Review Microsoft Office trusted publishers at least annually; remove unknown entries and confirm each certificate/publisher remains valid and required.

Mapping detail

Mapping

Direction

Controls