Manage active content — JavaScript, Office macros, Java — so only trusted code runs.
What it actually means
Mobile code — browser scripts, Office macros, Java applets — can carry malware. Define what's allowed and control it: disable Office macros sourced from the internet, restrict browser plugins, and block unsigned or untrusted active content. Modern endpoint and email protections handle most of this once configured.
Pass or fail — an assessor needs a "yes" to each
- Have you defined and restricted which mobile code is allowed (for example, macros blocked from the internet)?
- Are browser and endpoint protections configured to block untrusted active content?
What to have ready
- GPO / endpoint policy blocking internet-sourced macros
- Browser / email security configuration
Where teams trip up
- Office macros fully enabled across the org
- No stance on mobile code in policy or configuration
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in System & Communications Protection (3.13)
3.13.1 — Protect your boundaries3.13.2 — Build security in by design3.13.3 — Separate user and admin functions3.13.4 — Stop data leaking through shared resources3.13.5 — Wall off your public-facing systems3.13.6 — Deny all, permit by exception3.13.7 — Block split tunneling on VPNs3.13.8 — Encrypt CUI in transit3.13.9 — Drop idle network sessions3.13.10 — Manage your encryption keys3.13.11 — FIPS-validated cryptography3.13.12 — Control cameras and microphones3.13.14 — Control and monitor VoIP3.13.15 — Protect session authenticity3.13.16 — Encrypt CUI at rest