If you work in enterprise defense, you should absolutely do this. Almost none of your users will ever need to mount an ISO.
Those who have legitimate needs can use PowerShell or a third party tool. Huge risk reduction.
For those who missed the stream, an easy method to prevent mounting ISOs is to delete this registry value:
HKEY_CLASSES_ROOT\Windows.ISO.File\shell
Default value is "mount." Null it and Explorer will no longer mount ISOs on doubleclick. Still mounts from the command line.