HomeControl Library › 3.13.13
3.13 System & Communications Protection1 ptPOA&M-eligible

3.13.13 — Control mobile code

Control and monitor the use of mobile code.

Manage active content — JavaScript, Office macros, Java — so only trusted code runs.

What it actually means

Mobile code — browser scripts, Office macros, Java applets — can carry malware. Define what's allowed and control it: disable Office macros sourced from the internet, restrict browser plugins, and block unsigned or untrusted active content. Modern endpoint and email protections handle most of this once configured.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library