Skip to content
arrow_back
search
ISM-1890 policy ASD Information Security Manual (ISM)

Ensure Macros Are Free of Malicious Code

Verify that Microsoft Office macros are safe before signing or storing them in trusted locations.

record_voice_over

Plain language

This control ensures that any macros used in Microsoft Office documents are safe and free from malicious code before they're trusted or shared. If we don't check these macros, we risk hackers using them to access our systems and steal sensitive information or cause other damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.
policy ASD Information Security Manual (ISM) ISM-1890
priority_high

Why it matters

Unchecked Microsoft Office macros can run malicious code, enabling unauthorised access, ransomware, or data theft via trusted documents.

settings

Operational notes

Before signing or adding to Trusted Locations, review and test Office macros; use static analysis and malware scanning, then store approved versions.

Mapping detail

Mapping

Direction

Controls