ACSC Essential Eight
Application Control

ACSC Essential Eight APP-ML3: Application Control (ML3)

All ML2 requirements plus: Application control is implemented on non-internet-facing servers. Application control restricts the execution of drivers to an organisation-approved set. Microsoft's vulnerable driver blocklist is implemented. Event logs from non-internet-facing servers and from workstations are analysed in a timely manner to detect cyber security events.

Other controls in Application Control

You are reading one control. How much of ACSC Essential Eight have you already done?

ACSC Essential Eight APP-ML3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ACSC Essential Eight your existing evidence covers. Hold FedRAMP Moderate and 18 of 24 ACSC Essential Eight controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.