What is application control?
Where it stops an attack.
- The attack A phishing email drops a program into a user’s Downloads folder and tries to run it.
- Stopped here The program isn’t on the approved list, so Windows refuses to run it.
- The result No ransomware, no stolen passwords, no back door.
Application control maturity levels
What changes at each level.
Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)
How to implement application control
Protection first, disruption last.
- 01
Run in audit mode first
Record every application, script and installer the business uses before blocking anything. - 02
Build the allowlist
Allow by publisher certificate where possible, so routine vendor updates don’t break. - 03
Enforce in waves
Start with one team, fix what breaks, then roll out to the rest. - 04
Handle exceptions by ticket
A quick request process for new software, so nobody works around the control.
Common application control mistakes
Where rollouts go wrong.
-
Going straight to enforce
Skipping audit mode is how a line-of-business app stops working on a Monday.
-
Allowing folders users can write to
If staff can write there, so can malware.
-
Set and forget
Software changes. The rules need an owner.