Module 5 of StartCloud's Essential Eight for Australian Business learning pathway, in five short units with a knowledge check: the three controls that stop unwanted code running (application control, restrict Microsoft Office macros, user application hardening), an honest account of why application control is the hardest and most disruptive of the eight for a small business, how to roll it out by monitoring before blocking, what macro restriction actually means, plain-English hardening for browsers, PDF readers and Office, and a sensible order to tackle them in.

    What Is Allowed to Run

    Module 5 · ApplicationsUnit 1 of 5 · about 2 min

    Three controls, one job

    Three of the eight controls share a single job: stopping code you never asked for from running on your computers. Application control, restrict Microsoft Office macros, and user application hardening.

    Everything in the last two modules was about closing the ways in. These three assume something got through anyway, which it eventually will, and try to make sure it cannot do anything once it lands. That is a very different kind of protection, and it is the reason this group exists on the list at all.

    Application control

    Only approved software is allowed to run, and everything else is blocked by default. Not blocked because it looks suspicious, blocked because it is not on the list. This is the strongest of the three and easily the hardest to live with.

    Restrict Microsoft Office macros

    Macros are small programs that live inside Office documents. They were built to save people typing, and they have been used to deliver malware for a very long time. The control is about allowing only the ones you genuinely need.

    User application hardening

    Turning off features in browsers, PDF readers and Office that almost nobody uses and attackers rely on. Not new software, not new spending, just switching off doors nobody in your business walks through anyway.

    Antivirus and application control are not the same idea

    Antivirus works by recognising things it knows to be bad, so brand new malware gets a head start. Application control works the other way around. It allows what you have approved and blocks everything else, which means it does not need to have seen the threat before. That is the appeal, and it is also exactly why it is disruptive, because "everything else" includes plenty of software your team actually wanted.

    StartCloud Assistant

    Online

    G'day! 👋 I'm the StartCloud Assistant. How can I help you today?