Essential Eight Application Control: Why Antivirus Is Not the Same as Controlling What Runs
The Essential Eight is a prioritised set of mitigation strategies developed by the Australian Cyber Security Centre (ACSC) to assist organisations in protecting their systems against a range of cyber threats. Application Control sits at the top of this list, serving as one of the most effective technical controls available for securing modern business environments. For businesses in South East Queensland and beyond, understanding where Application Control fits within this framework is the first step toward moving beyond basic endpoint protection.
The Permissive Default: How Most SMBs Operate
In many small-to-medium businesses, the default state of the IT environment is permissive. This means that, by default, a user can download a piece of software from the internet, run an executable file from a USB drive, or install a new browser extension without any technical barrier or formal approval process.
This environment typically lacks:
- A documented allow list: There is no central record of which software is officially sanctioned for business use.
- A software request process: Employees often find their own "workarounds" or tools to solve immediate problems, leading to a fragmented software estate.
- Audit visibility: Management and IT teams often have no way of knowing what software is actually executing on company devices until a problem occurs.
- Centralised control: Administrative rights are often distributed too broadly, allowing staff to bypass security suggestions to install what they need.
In this permissive state, the business relies entirely on the individual's judgment and the hope that their antivirus will catch anything malicious. However, this approach creates a significant governance gap. It assumes that if a piece of software is not identified as "bad," it must be "good." In a modern threat landscape, that assumption is a high-risk foundation.
The Misconception: Antivirus and EDR Are Not Application Control
A common misconception among business owners is that having a modern antivirus or Endpoint Detection and Response (EDR) solution satisfies the requirement for Application Control. While these tools are essential components of a security stack, they perform a fundamentally different function.
Antivirus: Blocking the "Known Bad"
Antivirus and EDR tools are primarily reactive. They function by identifying "known bad" signatures or observing suspicious behaviours that match a threat profile. They are designed to detect and stop malware, ransomware, and other malicious actors once they have already attempted to execute or enter the system.
If a piece of software is new, custom-built for a specific attack, or simply a legitimate but unauthorised tool (such as a remote access utility used by an employee), the antivirus may not flag it. If the tool is not explicitly malicious, the antivirus will generally allow it to run.
Application Control: Permitting the "Known Good"
Application Control flips this logic. It is a proactive governance discipline that operates on the principle of an "allow list." Instead of trying to keep track of the millions of pieces of malware in existence, Application Control focuses on the small, defined list of software that the business has authorised.
If a file or script is not on the allow list, the system prevents it from executing. It does not matter if the software is "clean" or "malicious"; if it has not been explicitly permitted by the organisation, it does not run. This move from a block-everything-bad model to a permit-only-good model is the core requirement of the Essential Eight.
Application Control as a Governance Discipline
It is a mistake to view Application Control as a "set and forget" software tool. Effective implementation is a governance discipline that requires ongoing management and clear internal ownership. It involves four key pillars:
1. The Defined Allow List
The allow list is the master record of every executable, script, and installer permitted to run in the environment. This list should be based on objective criteria, such as the cryptographic hash of the file or the digital signature of the publisher (e.g., allowing all software signed by "Microsoft" or "Adobe").
2. The Software Request Process
Because business needs change, the allow list cannot remain static. A formal process must exist for staff to request new software. This process should evaluate the business need for the software, the reputation of the vendor, and the security implications of the tool before it is added to the list.
3. Clear Ownership
Someone must own the allow list. In an SMB environment, this is typically a designated IT manager or an external partner providing business IT support. Without a clear owner, the allow list quickly becomes outdated or is bypassed by staff who find the restrictions frustrating.
4. Visibility and Audit
Governance requires data. You need to be able to see when execution attempts were blocked and what software is currently running across your fleet. Monitoring these logs allows the business to refine the allow list and identify potential shadow IT: software being used for business purposes that hasn't gone through the proper channels.


Common Implementation Pitfalls in SMBs
Implementing Application Control is often cited as the most difficult of the Essential Eight to get right. Businesses often stumble because they treat it as a technical hurdle rather than a business process.
- Overly Broad Rules: To avoid "breaking" things, some businesses create rules that are too permissive, such as allowing anything in the "Downloads" folder to run. This effectively nullifies the security benefits of the control.
- Set and Forget: If the allow list isn't reviewed periodically, it will eventually contain legacy software that is no longer used or supported. These unpatched, "approved" applications can become a vulnerability.
- Lack of Communication: If staff do not understand why they can no longer install their own software, they may view IT as an obstacle to their work. Proper implementation includes explaining the "why" to the team.
- Permanent Exceptions: A user might need a specific tool for a one-off task. If the exception made for that task becomes permanent without review, the attack surface slowly grows over time.
Intersections with Other Essential Eight Elements
Application Control does not exist in a vacuum. Its effectiveness is tied to how well other Essential Eight strategies are implemented:
- Patch Management: Application Control ensures that only approved versions of software run. If you identify a vulnerability in a specific version of a tool, you can update your Application Control policy to block the old version and only allow the patched one.
- Restrict Administrative Privileges: If users have local administrative rights, they may be able to override or modify the Application Control settings. Restricting these privileges is necessary to ensure the allow list remains the authority on what executes.
- Microsoft Office Macro Settings: Macros are a specific type of executable code. Application Control policies often govern which macros are allowed to run based on their origin or digital signature, closing a common path for malware entry.
Practical First Steps for Your Business
If your business currently has no formal control over what software runs on its systems, jumping straight to a strict allow list can be disruptive. A phased approach is generally more successful.
- Baseline Your Environment: Use your existing monitoring tools to discover what software is currently installed and running on your devices. You cannot control what you have not identified.
- Define a Starter Allow List: Use your baseline to create an initial list of "known good" applications. This usually includes the operating system files, core productivity suites (like Microsoft 365), and your specific line-of-business applications.
- Establish a Request Route: Before you turn on "blocking" mode, tell your staff how they can request new software. Ensure they know there is a pathway to getting the tools they need.
- Implement in "Audit-Only" Mode: Most Application Control tools allow you to run in a mode that logs what would have been blocked without actually stopping it. This allows you to identify any legitimate software you missed during the baseline phase.
- Move to Enforced Mode: Once the logs are clean and the request process is working, move to active enforcement.
Application Control is about shifting the burden of proof from the security system to the software itself. By deciding that only trusted, verified, and business-critical software should run, you significantly reduce the risk of both external attacks and internal shadow IT risks.
If you are looking to move your business beyond basic antivirus and toward a structured governance model, you can speak with Moreton Bay IT to discuss a roadmap for implementing the Essential Eight in your environment.
