Security Readiness Report

Essential Eight · Application Control

Application Control

Your results, and how to close the gap.

Environment Windows & Mac Maturity Level 1 Prepared for a small business Format sample
Sample

This is a format preview, not a finished report. The technical steps are grounded in public ACSC, Microsoft and Apple documentation but are not yet verified, and a few facts are deliberately left marked as open so you can see how the report flags what it cannot yet source.

Report summary

Application control stops work computers running programs you have not approved. It is one of the strongest protections you can switch on, and the one most likely to be quietly rolled back, because that risk is mostly people and process, not the technology. So this plan leads with both.

Where you stand

Already strong

  • Windows PCs run Microsoft Defender and Macs run Gatekeeper, so a basic layer is already on both.
  • Staff already ask before installing software, so what runs is somewhat limited.

The gap: those layers warn and scan, but nothing yet firmly blocks an unapproved program from running, which is what this plan adds.

Strengths and gap are illustrative here; the real report draws them from your answers.

What it takes

Typical cost
Freebuilt into Windows & macOS
Approach
Pilot, then enforce
Coverage
Every work computer
Most-missed step
The exception path

The plan

Decisions to make

Who owns it, the budget, and the exception rule.

For owner
Bringing your team along

How to explain the change, and handle the blocks.

For owner
The technical setup

The hands-on steps for your IT, per platform.

For IT

The three parts weave together into one path, from decision to done, spelled out later in the report:

  1. Decide
  2. Prepare
  3. Pilot
  4. Announce
  5. Enforce
  6. Support & verify

Your rollout plan

Three parts, in order. The decisions and your team come first, then the technical setup, done per platform.

Pillar 1

Decisions to make

For the owner

The decisions only you can make. Nothing below starts without them.

Pillar 2

Bringing your team along

For the owner

Explain the change and why it matters, handle the blocked-program questions, and support people through it, so it sticks instead of getting switched back off.

Pillar 3

The technical setup

For IT / your provider

The hands-on steps for whoever sets it up. Windows and Mac are done differently, so each has its own track below. Every step carries its source, and open items are flagged, not guessed.

Windows AppLocker · WDAC · Defender ASR
  1. Application control on every Windows workstation. AppLocker path-based rules, or WDAC (App Control for Business), applied via Group Policy. Deploy in audit mode first, then enforcement.
    ACSC, Implementing application control · Microsoft, App Control for Business deployment guide
  2. Block execution from user-profile and temp folders. AppLocker deny rules on user-writable paths across the executable, script, installer and DLL collections. exact path list + file-type coverage: open
    Microsoft, Working with AppLocker rules
  3. Block executable content arriving by email. Enable the Defender ASR rule "Block executable content from email client and webmail".
    Microsoft, Attack surface reduction rules reference
  4. Verify safely. Confirm via audit-mode block events and the ACSC assessment method, no download-and-run test.
    Microsoft, deployment guide · ACSC, Essential Eight Assessment Process Guide
macOS Gatekeeper + MDM
Flag

ACSC's application-control guidance is written for Windows. On Mac, Gatekeeper plus MDM is the equivalent, applied as a compensating control, whether it meets a strict Level 1 assessment should be confirmed.

  1. Keep Gatekeeper on, and lock it with MDM. Gatekeeper already lets a Mac open only apps from an identified developer that Apple has notarised and that haven't been altered. A user can normally override it; your MDM takes that override away so it can't be switched off.
    Apple, Gatekeeper and runtime protection in macOS
  2. Allow trusted sources only. Set the Macs to accept the App Store and identified, notarised developers, and to refuse unsigned or un-notarised apps. exact MDM payload: open
    Apple, Protecting against malware in macOS
  3. Apply and hold it centrally. Push the policy from your MDM (Jamf, Kandji, Mosyle or Intune) so every Mac is the same, new and remote ones included, and staff can't loosen it. product-specific steps: open
  4. Verify safely. Confirm through your MDM's compliance view or device logs, not by downloading and running a test app.
    Apple, Mac app security enhancements
All three

From decision to done

The three parts above are not done in silos or one after another. This is the single order they weave into, the decisions and your team leading, the technical work threaded through.

  1. 1

    Decide

    Decisions

    Owner, approach, exception stance, policy line.

  2. 2

    Prepare

    Team

    Draft the staff message and the "blocked? contact X" path; brief IT.

  3. 3

    Pilot

    Setup + team

    Audit mode on a few machines, each platform separately; review what would be blocked; refine the rules and the exception list.

  4. 4

    Announce

    Team

    Message staff just before enforcing.

  5. 5

    Enforce

    Setup

    Switch to enforcement on each platform, rolling out in waves.

  6. 6

    Support & verify

    Team + setup

    Handle the first-week questions; confirm via block events; keep the rollback ready.

Sources

How this was made. The Windows steps are citation-grounded against ACSC and Microsoft; the Mac steps against Apple's Gatekeeper and deployment guidance, and the Mac track is flagged because ACSC's application-control guidance is written for Windows. The business and change-management steps are principle-based advice: ACSC's guidance backs the audit-mode pilot, exception handling and staff communication; the rest is established rollout practice, given as advice, not cited fact. Items marked open (cost, exact folder paths and MDM payloads, file-type coverage, the AppLocker Windows edition) are resolved from the source publications before a real report ships, never invented.