Skip to content

Application Control

What is Application Control?

Security measures that restrict which applications can execute on systems, preventing unauthorized or malicious software from running.

Information Security

What the standards actually require on application control

Requirements naming application control across 6 standards, quoted from the control text.

Application control restricts the execution of drivers to an organisation-approved set.

ISM-1658 · Application control restricts the execution of drivers to an organisation-approved set.

All ML2 requirements plus: Application control is implemented on non-internet-facing servers. Application control restricts the execution of drivers to an organisation-approved set. Microsoft's vulnerable driver blocklist is implemented.

E8-APP-ML3 · Application Control (ML3)

Application control to prevent execution of unapproved/malicious programs including .exe, DLL, scripts and installers.

ASD37-01 · Application control (Essential)
MITRE ATT&CK1 control

Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable o...

MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation · MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control

Restrict and tightly control utilities that can override system and application controls.

iso-27001-2022::8.18 · Use of privileged utility programs

Requires the use of utility programs capable of overriding system and application controls to be restricted and tightly controlled.

iso-27002-2022::8.18 · Use of privileged utility programs

Questions people ask about application control

What is Application Control?
Security measures that restrict which applications can execute on systems, preventing unauthorized or malicious software from running.
Why is Application Control important for compliance?
Application Control is a key concept in Information Security. Understanding application control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Application Control?
Application Control appears in the requirement text of Australian Information Security Manual, ACSC Essential Eight, ASD Strategies to Mitigate Cyber Security Incidents, MITRE ATT&CK, ISO 27001:2022. Across these standards we have identified 16 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Application Control?
Explore our compliance framework pages to see how application control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Application Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.