APP-ML2 Application Control (ML2)
All ML1 requirements plus: Application control is implemented on internet-facing servers. Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web brow
8
artefacts
5
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Application control policy export covering internet-facing servers (web, mail, VPN, RDS gateway) with mode set to Enforce · Cloud console / configuration management
- Evidence that Microsoft's recommended block rules (https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/applications-that-can-bypass-appcontrol) are imported into the ruleset · Cloud console / configuration management
- SIEM dashboard or query showing AppLocker / WDAC events ingested from workstations and internet-facing servers · Endpoint management (MDM / EDR)
- Log retention configuration showing logs are write-once or otherwise protected from modification and deletion · SIEM / log platform
- Sample tickets showing an application control event was triaged from SIEM to incident closure with ASD report (if reportable) · SIEM / log platform
periodic reviewEvidence produced at each review
- Annual ruleset review record: date, reviewer, list of changes, sign-off · Cloud console / configuration management
governing documentDocuments that govern the control
- Inventory of internet-facing servers cross-referenced to enforcement coverage · Policy repository / GRC workspace
- Incident response plan with a defined Essential Eight trigger and last-tested date · Policy repository / GRC workspace
First move
Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.
Common gaps auditors find
- Internet-facing servers not in scope or in Audit Only mode
- Microsoft recommended blocklist not implemented or out of date
- Annual ruleset review not performed, rules drift uncontrolled
- Logs collected centrally but not protected from deletion by administrators
- Incidents reported to internal CISO but ASD notification step omitted
- Internet-facing server logs sent but not actively analysed (no use cases, no alerts)
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAPP-ML1 Application Control (ML1) · APP-ML3 Application Control (ML3)