It's Application Control the module that has that setting, and here is how I have it:
But, maybe sometimes some trust/signed applications will be moved to restriction groups, I constantly check my Application Control to see what's happening there, untrusted or trsuted applications, startup blocked applications, etc.... that's the price We have to pay of being paranoid

I have no problem with this...
About KSN
rules, yes is cloud/internet dependent, but I think/guess if You don't have internet in a moment, Kaspersky has a local cache of the last synchronization.
And yes, obviously disabling it will affect analyze... then a heuristic analyze will be performed when a new application is started, but You will not have the KSN benefits such as Application Whitelisting, Urgent Detection System (UDS detections), etc.
More info here:
http://www.kaspersky.com/images/KESB_Whitepaper_KSN_ENG_final.pdf