Application Allowlisting
What is Application Allowlisting?
A security practice that permits only pre-approved applications to execute on a system while blocking all other software from running.
Terms that appear alongside application allowlisting
Each of these is named in at least one of the same controls as application allowlisting. The number is how many controls name both.
- malware 6 shared controls
- anti malware 4 shared controls
- patch management 3 shared controls
- baseline 3 shared controls
- cybersecurity 3 shared controls
- policy 2 shared controls
- hardening 2 shared controls
- integrity 2 shared controls
Frameworks that govern application allowlisting
What the standards actually require on application allowlisting
Requirements naming application allowlisting across 6 standards, quoted from the control text.
Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained.
CE-MP.4 · Application Allowlisting (Alternative) →Deploy application allowlisting (AWL) to detect and prevent execution of malware uploaded by adversaries; static systems such as HMI computers and database servers are ideal candidates.
CISA-ICS-7S-1 · Implement Application Allowlisting (Whitelisting) →Use application allowlisting on stable OT endpoints to prevent execution of unauthorised software, particularly where signature-based anti-malware is constrained.
OT-HOST-2 · Application Allowlisting →Deploy and maintain anti-malware on IT endpoints and approved application allowlisting on OT endpoints.
AWWA-G430-8 · Malware Protection →Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
CIS-2.5 · Allowlist Authorized Software →Disclose and operate malware detection + system hardening + cybersecurity upgrade features per MDS2 MLDP + SAHD + CSUP sections. Malware Detection and Protection (MLDP) including anti-malware software support + signature update mechanism + behavioural detectio...
MDS2-Malware-Detection-MLDP-System-Hardening-SAHD-Cybersecurity-Upgrades-CSUP-Patch-Management · MDS2 Malware Detection + MLDP + System Hardening + SAHD + Cybersecurity Upgrades + CSUP + Patch Management →Questions people ask about application allowlisting
What is Application Allowlisting?
Why is Application Allowlisting important for compliance?
Which compliance frameworks address Application Allowlisting?
Where can I learn more about Application Allowlisting?
See how Application Allowlisting applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.