Application allowlisting
Also known as Whitelisting
Permitting only approved software to run, and blocking everything else by default.
It inverts the usual model. Rather than trying to identify what is bad, you define what is permitted, which neutralizes brand-new malware because it simply is not on the list.
The cost is administrative. Every legitimate new application and update needs handling, so it fits tightly controlled environments such as clinical workstations and point-of-sale systems far better than a general knowledge-worker estate.
Where this comes up
Application allowlisting sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.