Course Content
Understanding the Defence Industry Security Programming (DISP)
This topic explains the Defence Industry Security Program (DISP). Explains what DISP does for the industry and which entities may apply for DISP membership.
0/4
Conduct An Initial Review of a Cyber Security Questionnaire (CSQ)
During this topic you will be taught about the Cyber Security Questionnaire, and how to conduct an initial review of a submitted questionnaire.
0/4
Conduct A Quality Assurance (QA) Check of an Initial Assessment (IA)
During this topic you'll be taught how to carry out a Quality Assurance (QA) Check of an Initial Assessment (IA).
0/6
Entry Level Assessors Course
Please login for access. Login
About Lesson

Application control (formerly referred to as application whitelisting) is a security principle designed to protect against malicious and/or unwanted code executing on systems. When implemented correctly it ensures that only approved applications (e.g. executables, software libraries, scripts and installers) can be executed. While it is primarily designed to prevent the execution and spread of malicious code, it can also prevent the installation or use of unapproved applications. 

For example: 

Recommendation – Application Control 

It is recommended that the organisation implements application control on all workstations and servers.  

Application Control is identifying approved applications and developing application control rules to ensure only approved applications are allowed to execute. 

Implementation Outcome 

Application control is implemented on all workstations to restrict the execution of executables to an approved set. Application control is implemented on all servers to restrict the execution of executables to an approved set. Application control can prevent the execution of unapproved/malicious programs including .exe, DLL, scripts (e.g. Windows Script Host, PowerShell and HTA) and installers. All non-approved applications (including malicious code) are prevented from executing. 

 

Join the conversation