Application control
Application control means your computers only run software the business has approved. Most security tools try to catch bad software. This one works the other way round: if a program is not on the approved list, it does not run. It is one of the most effective defences against ransomware and malicious downloads.
It is control 1 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
It blocks unapproved programs outright, so at the higher maturity levels insurers commonly read application control as a strong sign of a hardened environment.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Do staff computers only allow approved programs to run (application control / allow-listing)?
ACSC requirement: “Application control is implemented on workstations.”
Does that control cover all executable file types (programs, scripts, installers and similar), limiting them to an approved set?
ACSC requirement: “Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is Microsoft's recommended application blocklist applied, blocking known-risky tools?
ACSC requirement: “Microsoft's recommended application blocklist is implemented.”
Are your application control rules reviewed at least once a year?
ACSC requirement: “Application control rulesets are validated on an annual or more frequent basis.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Is Microsoft's vulnerable driver blocklist applied?
ACSC requirement: “Microsoft's vulnerable driver blocklist is implemented.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).