Restrict Microsoft Office macros
Microsoft Office macros are small programs tucked inside documents and spreadsheets. They are also a favourite way to deliver malware: a booby-trapped invoice or résumé that runs code the moment someone clicks "enable". This control limits which macros can run, especially in files that came from the internet.
It is control 3 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Macro-based phishing is still one of the leading ways attackers get into Australian businesses, so insurers often ask how you restrict macros. If your business does not use Microsoft Office, this control may not apply to you.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Are Office macros turned off for staff who don't have a genuine business need for them?
ACSC requirement: “Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.”
Are Office macros in files downloaded from the internet (including email attachments) blocked from running?
ACSC requirement: “Microsoft Office macros in files originating from the internet are blocked.”
Does your antivirus software scan Office macros?
ACSC requirement: “Microsoft Office macro antivirus scanning is enabled.”
Are staff prevented from changing macro security settings themselves?
ACSC requirement: “Microsoft Office macro security settings cannot be changed by users.”
Maturity Level 2: the common target
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Are Office macros blocked from making low-level Windows system calls (Win32 API)?
ACSC requirement: “Microsoft Office macros are blocked from making Win32 API calls.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
Can macros only run if they're digitally signed by a trusted publisher, stored in a Trusted Location, or sandboxed?
ACSC requirement: “Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).