Skip to content

Allow List

What is Allow List?

A cybersecurity approach that permits only pre-approved applications, IP addresses, or entities to access a system while blocking all others by default.

Information Security

What the standards actually require on allow list

Requirements naming allow list across 6 standards, quoted from the control text.

As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.

CEP-MA-02 · Application Allow Listing or Sandboxing

Ensure only authorised software executes in virtual machines by maintaining an allow list and blocking unauthorised software from running.

ASBv3-AM-5 · Use only approved applications in virtual machine

UR E26 Goal 2 (Protect) requires malware defence + patch management + vulnerability management + system hardening. Malware defence: anti-malware (signature + heuristic + behavioral) deployed on CBS where supported;

IACS-UR-E26-Protect-Malware-Patch-VulnMgmt-Hardening · IACS UR E26 Protect Goal - Malware Defence + Patch + Vulnerability Management + Hardening + Whitelisting

Address OWASP Top 10 A08 Software and Data Integrity Failures per OWASP Top 10:2025. Software and Data Integrity Failures arise from assumptions about software updates + critical data + CI/CD pipelines without verifying integrity including unsigned updates + i...

OWASPTOP10-8 · A08:2025 Software and Data Integrity Failures
SWIFT CSCF1 control

Implement business level controls on payment activity, including allow listed counterparties, value limits, time windows, and dual authorisation for high risk transactions.

CSCF-2.9 · Transaction Business Controls

Block internet access to the firewall administrative interface unless there is a clear documented business need, and where allowed protect it with multi-factor authentication or a restricted IP allow list combined with managed password authentication.

CE-FW.7 · Restrict Firewall Administrative Interface from the Internet

Questions people ask about allow list

What is Allow List?
A cybersecurity approach that permits only pre-approved applications, IP addresses, or entities to access a system while blocking all others by default.
Why is Allow List important for compliance?
Allow List is a key concept in Information Security. Understanding allow list helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Allow List?
Allow List appears in the requirement text of Cyber Essentials Plus, Azure Security Benchmark, IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, OWASP Top 10:2025, SWIFT CSCF. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Allow List?
Explore our compliance framework pages to see how allow list applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Allow List applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.