Skip to content
arrow_back
ISM-1676policyASD Information Security Manual (ISM)

Validate Microsoft Office Trusted Publishers List At Least Annually

Check the list of trusted publishers in Microsoft Office at least once a year so only approved software signers can run code automatically.

record_voice_over

Plain language

Microsoft Office keeps a list of "trusted publishers": software companies or developers whose signed add-ins and macros (small programs inside Office files) are allowed to run automatically without warning the user. This control says you must review that list at least once every year to make sure every entry is still meant to be there. If an outdated, unknown or malicious publisher stays on the list, harmful code could run silently on staff computers, so checking it annually keeps the list trustworthy.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

19 June 2026

E8 maturity levels

ML3

Official control statement

Microsoft Office's list of trusted publishers is validated at least annually.
policyASD Information Security Manual (ISM)ISM-1676
priority_high

Why it matters

If the trusted publishers list is never reviewed, an unknown or malicious signer could remain trusted and run harmful macros or add-ins on staff computers without any warning.

settings

Operational notes

Run this validation at least once a year, and also re-check the list after major Microsoft Office upgrades or changes to which add-ins your organisation uses.

build

Implementation tips

  • The IT administrator should locate where the trusted publishers list lives in Microsoft Office (the Trust Center settings on each computer, or the central Group Policy or Microsoft Intune configuration if the list is managed organisation-wide) so they know exactly what they are reviewing.
  • The IT administrator should schedule a recurring annual reminder (for example a calendar entry or ticket in the IT system) so the trusted publishers review happens on time every year and is not forgotten.
  • During each review, the IT administrator should compare every publisher on the list against an approved baseline and remove any entry that is unknown, no longer used, expired or was added without authorisation.
  • Where possible, the IT manager should lock down the list centrally using Group Policy or Microsoft Intune so individual staff cannot quietly add their own trusted publishers between annual reviews.
  • After each review, the person who performed it should record the date, who did it, what was found and any entries removed, then have a manager sign off so there is proof the validation actually took place.
fact_check

Audit / evidence tips

  • Askthe IT administrator to show the current list of trusted publishers configured in Microsoft Office (on a sample of computers or in the central management console)Goodis a short, clearly justified list where every publisher is recognised and approved
  • Askrecords of the most recent annual validation, including the date it was performedGoodshows the last review happened within the past 12 months, not longer ago
  • Askwho is responsible for performing the review and how it is scheduledGoodnames a specific role and points to a recurring reminder or calendar entry that triggers the check each year
  • Askwhat happens when an unrecognised or unwanted publisher is found during the reviewGooddescribes a clear process to remove it and document the change
  • Askhow the list is prevented from being changed by ordinary staff between reviewsGoodshows the list is enforced centrally through Group Policy or Microsoft Intune rather than left editable on each individual computer
link

Cross-framework mappings

How ISM-1676 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-AC-ML2.4E8-AC-ML2.4 requires organisations to validate their application control rulesets annually or more frequently
handshakeSupports(2)expand_less
E8-RM-ML3.1ISM-1676 requires organisations to periodically validate which publishers are trusted in Microsoft Office
E8-RM-ML3.4E8-RM-ML3.4 requires that macros signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View
linkRelated(1)expand_less
E8-RM-ML3.6ISM-1676 requires Microsoft Office’s list of trusted publishers to be validated at least annually

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls