Glossary · OT security engineering
Application allowlisting
Also known as: Application whitelisting, Allowlisting
German: Anwendungsfreigabeliste
In endpoint security, application allowlisting is a control that permits only explicitly approved applications, scripts and libraries to run on a system and blocks everything else. It suits OT hosts such as HMIs and engineering stations, whose software rarely changes.
- Security engineering
- OT security
In one sentence
Application allowlisting lets only approved applications, scripts and libraries run on a system, a good fit for OT hosts whose software rarely changes.
Example
On the line's HMI PCs, allowlisting permits only the SCADA runtime and approved tools, so a ransomware executable copied from a USB stick cannot start.
How it applies
- Engineering: Allowlists identify approved software by attributes such as file hash, publisher signature or path. Signature-based rules are easier to maintain across updates than hash lists. NIST SP 800-167 gives guidance on planning and implementing allowlisting.
- Operation: Allowlisting is a strong compensating measure for OT systems that cannot be patched quickly, because it blocks unknown malware without depending on signature updates like antivirus.
- Maintenance: Every software update must update the allowlist, or the updated application will be blocked. Tie allowlist changes to Change control and test them on a reference system first.
- Documentation: Automation software vendors should document which executables, services and paths their product uses and whether allowlisting tools are supported. Update instructions should remind users to adjust the allowlist before installing.
Allowlisting vs. antivirus
Antivirus blocks known bad software (denylist). Allowlisting permits only known good software. In OT, allowlisting is often preferred because the set of legitimate software is small and stable.