EvidenceSheet

APP-ML1 Application Control (ML1)

Application control is implemented on workstations. Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. Application control restricts the execu

8
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Application control product configuration export (Microsoft AppLocker XML, Windows Defender Application Control policy XML, Carbon Black or AirLock ruleset) · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • Documented approved application list with owner, last review date and approval workflow · Policy repository / GRC workspace
  • Screenshot or export showing rules covering user profiles (C:\Users, AppData) and temporary folders (Temp, Downloads) · Policy repository / GRC workspace

governing documentDocuments that govern the control

  • List of workstations in scope, cross-referenced to asset inventory and CMDB to evidence full coverage · Policy repository / GRC workspace
  • GPO or MDM policy showing application control is in Enforce mode (not Audit Only) on workstations · Policy repository / GRC workspace
  • Sample of allowed and blocked events from workstation Event Viewer (Microsoft-Windows-AppLocker/EXE and DLL, MSI and Script channels) · Policy repository / GRC workspace
  • Evidence that rule scope covers all required file types: .exe, .dll, .ps1, .vbs, .js, .msi, .chm, .hta, .cpl · Policy repository / GRC workspace
  • Exception register listing approved exceptions, owner, business justification, expiry and compensating control · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Cloud console / configuration management on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

ADMIN-ML3 Restrict Administrative Privileges (ML3) · APP-ML2 Application Control (ML2)