Application Allowlisting
Application allowlisting is a security control that allows only explicitly approved software to execute on a system and blocks everything else by default, making it well suited to stable OT workstations and servers.
Application allowlisting, formerly often called whitelisting, is a security control that permits only approved software to run on a system and blocks everything else by default. Approval is based on attributes such as cryptographic file hashes, digital signatures from trusted publishers or protected file paths. Executables, scripts, libraries and installers that are not on the list are prevented from running, which stops most malware and unauthorised tools even when they are new and unknown to antivirus signatures.
Allowlisting is particularly suited to OT systems such as HMIs, engineering workstations, historians and SCADA servers, because their software changes rarely and they often run older operating systems that cannot be patched promptly or support modern endpoint agents. It is a common compensating control for unpatched systems. NIST SP 800-167 provides guidance on application whitelisting, and Microsoft AppLocker and Windows Defender Application Control implement it on Windows.
Deployment needs a careful baseline of legitimate software, a period in audit mode to catch missing entries and a process for updates, since patches and vendor upgrades change file hashes. Allowlisting should be coordinated with the control system vendor, which may publish compatibility guidance. It does not stop attacks that abuse approved tools or exploit vulnerabilities in memory, so it complements rather than replaces patching and monitoring.
Key points
- Only approved executables, scripts and libraries are allowed to run
- Approval is based on file hashes, publisher signatures or protected paths
- Well suited to HMIs, engineering workstations and SCADA servers that change rarely
- NIST SP 800-167 provides guidance on application whitelisting
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Deny-by-Default ControlOT & Industrial Cybersecurity
- Engineering Workstation SecurityOT & Industrial Cybersecurity
- OT Patch ManagementOT & Industrial Cybersecurity
- Defence in DepthOT & Industrial Cybersecurity
- Supervisory Control and Data Acquisition (SCADA)PLC & Industrial Control