APP-ML3 Application Control (ML3)
All ML2 requirements plus: Application control is implemented on non-internet-facing servers. Application control restricts the execution of drivers to an organisation-approved set. Microsoft's vulnerable driver blocklis
8
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- SIEM evidence showing event analysis use cases against non-internet-facing server logs and workstation logs · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Application control enforcement evidence for non-internet-facing servers (file, print, AD, database) with mode set to Enforce · Cloud console / configuration management
governing documentDocuments that govern the control
- Windows Defender Application Control policy or equivalent showing driver control restrictions to an approved driver set · Policy repository / GRC workspace
- Microsoft vulnerable driver blocklist policy imported and active (HVCI / Smart App Control or WDAC driver blocklist) · Policy repository / GRC workspace
- Driver inventory with vendor, signature status and approval status · Vendor register / contract repository
- Documented Secure Admin Workstation or jump path used to deploy and update WDAC policies · Policy repository / GRC workspace
- Last validation of driver allowlist and Microsoft vulnerable driver blocklist against current Microsoft published version · Policy repository / GRC workspace
- End-to-end incident sample: workstation AppLocker block to SIEM to triage to IR plan to ASD report · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Non-internet-facing servers excluded as too disruptive to enforce
- Driver allowlist not implemented, BYOVD attack path remains
- Microsoft vulnerable driver blocklist not enabled or version out of date
- Workstation events ingested into SIEM but no detection use cases configured
- WDAC policies signed but signing keys not rotated or held in HSM
- Annual ruleset validation performed but no record of driver rules being reviewed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAPP-ML2 Application Control (ML2) · BACKUP-ML1 Regular Backups (ML1)