APP-ML1 Application Control (ML1)
Application control is implemented on workstations. Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients. Application control restricts the execu
8
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Application control product configuration export (Microsoft AppLocker XML, Windows Defender Application Control policy XML, Carbon Black or AirLock ruleset) · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Documented approved application list with owner, last review date and approval workflow · Policy repository / GRC workspace
- Screenshot or export showing rules covering user profiles (C:\Users, AppData) and temporary folders (Temp, Downloads) · Policy repository / GRC workspace
governing documentDocuments that govern the control
- List of workstations in scope, cross-referenced to asset inventory and CMDB to evidence full coverage · Policy repository / GRC workspace
- GPO or MDM policy showing application control is in Enforce mode (not Audit Only) on workstations · Policy repository / GRC workspace
- Sample of allowed and blocked events from workstation Event Viewer (Microsoft-Windows-AppLocker/EXE and DLL, MSI and Script channels) · Policy repository / GRC workspace
- Evidence that rule scope covers all required file types: .exe, .dll, .ps1, .vbs, .js, .msi, .chm, .hta, .cpl · Policy repository / GRC workspace
- Exception register listing approved exceptions, owner, business justification, expiry and compensating control · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Cloud console / configuration management on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Application control deployed in Audit Only mode rather than Enforce
- Coverage missing scripts (.ps1, .vbs, .js), MSI installers, HTA or CPL files
- User profile and temporary folder paths not enforced, allowing LOLBins from AppData
- No formal approved application list, rules built ad hoc by IT
- Exceptions granted without expiry or compensating control
- Allowed and blocked events not collected centrally, only available on the endpoint
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetADMIN-ML3 Restrict Administrative Privileges (ML3) · APP-ML2 Application Control (ML2)