Allow List
What is Allow List?
A cybersecurity approach that permits only pre-approved applications, IP addresses, or entities to access a system while blocking all others by default.
Frameworks that govern allow list
What the standards actually require on allow list
Requirements naming allow list across 6 standards, quoted from the control text.
As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.
CEP-MA-02 · Application Allow Listing or Sandboxing →Ensure only authorised software executes in virtual machines by maintaining an allow list and blocking unauthorised software from running.
ASBv3-AM-5 · Use only approved applications in virtual machine →UR E26 Goal 2 (Protect) requires malware defence + patch management + vulnerability management + system hardening. Malware defence: anti-malware (signature + heuristic + behavioral) deployed on CBS where supported;
IACS-UR-E26-Protect-Malware-Patch-VulnMgmt-Hardening · IACS UR E26 Protect Goal - Malware Defence + Patch + Vulnerability Management + Hardening + Whitelisting →Address OWASP Top 10 A08 Software and Data Integrity Failures per OWASP Top 10:2025. Software and Data Integrity Failures arise from assumptions about software updates + critical data + CI/CD pipelines without verifying integrity including unsigned updates + i...
OWASPTOP10-8 · A08:2025 Software and Data Integrity Failures →Implement business level controls on payment activity, including allow listed counterparties, value limits, time windows, and dual authorisation for high risk transactions.
CSCF-2.9 · Transaction Business Controls →Block internet access to the firewall administrative interface unless there is a clear documented business need, and where allowed protect it with multi-factor authentication or a restricted IP allow list combined with managed password authentication.
CE-FW.7 · Restrict Firewall Administrative Interface from the Internet →Questions people ask about allow list
What is Allow List?
Why is Allow List important for compliance?
Which compliance frameworks address Allow List?
Where can I learn more about Allow List?
See how Allow List applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.