Skip to content

Application Allowlisting

What is Application Allowlisting?

A security practice that permits only pre-approved applications to execute on a system while blocking all other software from running.

Information Security

Each of these is named in at least one of the same controls as application allowlisting. The number is how many controls name both.

What the standards actually require on application allowlisting

Requirements naming application allowlisting across 6 standards, quoted from the control text.

Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained.

CE-MP.4 · Application Allowlisting (Alternative)

Deploy application allowlisting (AWL) to detect and prevent execution of malware uploaded by adversaries; static systems such as HMI computers and database servers are ideal candidates.

CISA-ICS-7S-1 · Implement Application Allowlisting (Whitelisting)

Use application allowlisting on stable OT endpoints to prevent execution of unauthorised software, particularly where signature-based anti-malware is constrained.

OT-HOST-2 · Application Allowlisting

Deploy and maintain anti-malware on IT endpoints and approved application allowlisting on OT endpoints.

AWWA-G430-8 · Malware Protection

Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.

CIS-2.5 · Allowlist Authorized Software

Disclose and operate malware detection + system hardening + cybersecurity upgrade features per MDS2 MLDP + SAHD + CSUP sections. Malware Detection and Protection (MLDP) including anti-malware software support + signature update mechanism + behavioural detectio...

MDS2-Malware-Detection-MLDP-System-Hardening-SAHD-Cybersecurity-Upgrades-CSUP-Patch-Management · MDS2 Malware Detection + MLDP + System Hardening + SAHD + Cybersecurity Upgrades + CSUP + Patch Management

Questions people ask about application allowlisting

What is Application Allowlisting?
A security practice that permits only pre-approved applications to execute on a system while blocking all other software from running.
Why is Application Allowlisting important for compliance?
Application Allowlisting is a key concept in Information Security. Understanding application allowlisting helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Application Allowlisting?
Application Allowlisting appears in the requirement text of UK Cyber Essentials, CISA Industrial Control Systems (ICS) Security Guidance, NIST SP 800-82 Rev 3, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CIS Controls v8. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Application Allowlisting?
Explore our compliance framework pages to see how application allowlisting applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Application Allowlisting applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.