Validate Microsoft Office Trusted Publishers List At Least Annually
Check the list of trusted publishers in Microsoft Office at least once a year so only approved software signers can run code automatically.
Plain language
Microsoft Office keeps a list of "trusted publishers": software companies or developers whose signed add-ins and macros (small programs inside Office files) are allowed to run automatically without warning the user. This control says you must review that list at least once every year to make sure every entry is still meant to be there. If an outdated, unknown or malicious publisher stays on the list, harmful code could run silently on staff computers, so checking it annually keeps the list trustworthy.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
19 June 2026
E8 maturity levels
ML3
Guideline
Guidelines for system hardeningSection
User Application HardeningOfficial control statement
Microsoft Office's list of trusted publishers is validated at least annually.
Why it matters
If the trusted publishers list is never reviewed, an unknown or malicious signer could remain trusted and run harmful macros or add-ins on staff computers without any warning.
Operational notes
Run this validation at least once a year, and also re-check the list after major Microsoft Office upgrades or changes to which add-ins your organisation uses.
Implementation tips
- The IT administrator should locate where the trusted publishers list lives in Microsoft Office (the Trust Center settings on each computer, or the central Group Policy or Microsoft Intune configuration if the list is managed organisation-wide) so they know exactly what they are reviewing.
- The IT administrator should schedule a recurring annual reminder (for example a calendar entry or ticket in the IT system) so the trusted publishers review happens on time every year and is not forgotten.
- During each review, the IT administrator should compare every publisher on the list against an approved baseline and remove any entry that is unknown, no longer used, expired or was added without authorisation.
- Where possible, the IT manager should lock down the list centrally using Group Policy or Microsoft Intune so individual staff cannot quietly add their own trusted publishers between annual reviews.
- After each review, the person who performed it should record the date, who did it, what was found and any entries removed, then have a manager sign off so there is proof the validation actually took place.
Audit / evidence tips
- Askthe IT administrator to show the current list of trusted publishers configured in Microsoft Office (on a sample of computers or in the central management console)Goodis a short, clearly justified list where every publisher is recognised and approved
- Askrecords of the most recent annual validation, including the date it was performedGoodshows the last review happened within the past 12 months, not longer ago
- Askwho is responsible for performing the review and how it is scheduledGoodnames a specific role and points to a recurring reminder or calendar entry that triggers the check each year
- Askwhat happens when an unrecognised or unwanted publisher is found during the reviewGooddescribes a clear process to remove it and document the change
- Askhow the list is prevented from being changed by ordinary staff between reviewsGoodshows the list is enforced centrally through Group Policy or Microsoft Intune rather than left editable on each individual computer
Cross-framework mappings
How ISM-1676 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| E8-AC-ML2.4 | E8-AC-ML2.4 requires organisations to validate their application control rulesets annually or more frequently | |
handshakeSupports(2)expand_less | ||
| E8-RM-ML3.1 | ISM-1676 requires organisations to periodically validate which publishers are trusted in Microsoft Office | |
| E8-RM-ML3.4 | E8-RM-ML3.4 requires that macros signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View | |
linkRelated(1)expand_less | ||
| E8-RM-ML3.6 | ISM-1676 requires Microsoft Office’s list of trusted publishers to be validated at least annually | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.