Home › Resources › Essential Eight › Application control

Application control

One of the eight mitigation strategies in the Essential Eight, checked against 3 tests at Maturity Level One.

Application control means only software your organisation has approved is permitted to run. Everything else, malware included, along with tools staff install on their own, is stopped before it can execute.

Why it matters

It is the single most effective defence against ransomware and drive-by malware, which is why it heads the list. For an organisation running shared or kiosk devices across several sites, it stops an infected download from ever running.

Where Intelligence Group fits

  • Inventory the applications each role genuinely needs
  • Move from a blocklist to an allowlist of approved executables, scripts and installers
  • Start with user profile locations, where most malware executes
  • Log what gets blocked and review it so the allowlist can be tuned
  • Keep the ruleset under change control so every approval is recorded
Where Intelligence Group fits

Intelligence Group rates this strategy from the evidence your organisation already generates, reports the maturity level it supports, and sets out the next step to lift it.

Official guidance: ASD Essential Eight Maturity Model