ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.23 Web filtering

ISO 27001 Annex A 8.23 Web filtering

What is ISO 27001 Annex A 8.23 – Web Filtering?

ISO 27001 Annex A 8.23 focuses on managing access to external websites to reduce exposure to malicious or inappropriate online content.

Organizations should manage access to external websites to protect users and information systems from risks such as:

  • Malware
  • Phishing
  • Malicious downloads
  • Command-and-control infrastructure
  • Fraudulent websites
  • Unauthorized software
  • Inappropriate content
  • Websites presenting significant security risks

Simple explanation

A.8.23 means the organization should control or manage access to websites that may create information-security risks.

This does not necessarily mean blocking large numbers of websites.

The organization should implement web filtering based on its security risks, business requirements, and acceptable-use rules.


Why is Web Filtering Important?

Employees frequently access the Internet for:

  • Research
  • Business applications
  • Cloud services
  • Social media
  • File sharing
  • Software downloads
  • Email
  • Collaboration
  • Customer support

Uncontrolled web access can expose the organization to:

  • Phishing attacks
  • Malware
  • Drive-by downloads
  • Credential theft
  • Malicious advertisements
  • Data leakage
  • Access to known malicious domains
  • Unauthorized applications
  • Security-policy violations

For example:

Employee receives phishing email

↓

Clicks malicious link

↓

Malicious website

↓

Credential theft / malware

Web filtering can provide an additional layer of protection by blocking known malicious or inappropriate destinations.


What does A.8.23 require?

The organization should determine whether web access needs to be controlled and implement appropriate filtering mechanisms based on its risks.

The organization should consider:

  • Types of websites that create security risks
  • Categories that should be blocked
  • How exceptions are managed
  • Who can change filtering rules
  • How filtering is monitored
  • How blocked requests are handled
  • How filtering effectiveness is reviewed

The control should be implemented in a way that supports legitimate business activities.


Activities Required to Implement A.8.23

1. Establish acceptable web-use requirements

Define how organizational systems and devices may be used to access external websites.

This may be documented in:

  • Acceptable Use Policy
  • Information Security Policy
  • Internet Usage Policy
  • Endpoint Security Standard

The policy should explain acceptable and prohibited activities.


2. Identify risky website categories

Organizations can use categories to manage web access.

Examples include:

CategoryExample Treatment
Known malicious sitesBlock
Phishing sitesBlock
Malware distributionBlock
Command-and-control sitesBlock
Illegal contentBlock where appropriate
High-risk downloadsRestrict
Newly registered/suspicious domainsConsider blocking/restricting
Adult contentBlock according to policy
GamblingBlock according to policy
Social mediaBusiness-dependent
File-sharing servicesBusiness-dependent
StreamingBusiness-dependent
Personal emailBusiness-dependent

The categories should be appropriate for the organization’s business and legal environment.


3. Implement web-filtering technology

Web filtering can be implemented through:

  • Secure Web Gateways
  • DNS filtering
  • Web proxies
  • Firewall filtering
  • Cloud-based security services
  • Endpoint security solutions
  • Browser security controls
  • Secure Access Service Edge (SASE) solutions
  • Cloud access security solutions

A startup does not necessarily need an expensive enterprise Secure Web Gateway.

A suitable cloud-based DNS or endpoint filtering solution may be sufficient depending on risk.


4. Apply filtering to relevant users and devices

Determine which devices should be covered.

For example:

  • Company laptops
  • Company desktops
  • Corporate mobile devices
  • Virtual desktops
  • Remote employee devices
  • Servers, where applicable

Remote employees should not automatically be excluded simply because they are working outside the office.


5. Configure block and allow rules

The organization should define:

Block

Known malicious and high-risk destinations.

Allow

Websites required for legitimate business activities where necessary.

Exception

A controlled process for legitimate websites that are incorrectly blocked.

For example:

Employee requests access

↓

Business justification

↓

Security review

↓

Approval

↓

Temporary/permanent exception

↓

Document decision


6. Protect against malicious websites

Filtering should help identify or block threats such as:

  • Phishing domains
  • Malware sites
  • Malicious downloads
  • Botnet infrastructure
  • Command-and-control destinations
  • Known fraudulent websites

Where available, threat-intelligence feeds can improve filtering effectiveness.


7. Monitor web-filtering events

Depending on risk and privacy requirements, the organization may monitor:

  • Blocked requests
  • Malware detections
  • Phishing attempts
  • High-risk website access
  • Policy violations
  • Filtering exceptions
  • Administrative changes

Monitoring should comply with applicable privacy, employment and legal requirements.


8. Review filtering rules

Filtering rules should be reviewed periodically and after significant events.

Review:

  • Blocked categories
  • Allow lists
  • Exceptions
  • Administrative changes
  • Security events
  • False positives
  • Business requirements

Remove unnecessary exceptions.


Example – SaaS Startup

Consider a SaaS company with 50 employees working from different locations.

Employees use:

  • Company laptops
  • Microsoft 365
  • GitHub
  • AWS
  • Slack
  • Browser-based business applications

The company implements cloud-based DNS/web filtering.

Security policy

The organization blocks:

  • Known malicious websites
  • Phishing domains
  • Malware distribution sites
  • Command-and-control destinations
  • Other high-risk categories defined by policy

Employees can access normal business websites.

If a legitimate website is blocked:

Employee submits request

↓

Business justification

↓

Security review

↓

Approval

↓

Exception recorded

The organization reviews filtering events periodically.

This gives the company a practical web-filtering control without requiring a large on-premises security infrastructure.


What Events Should Trigger Action or Review?

TriggerPossible Action
Phishing campaignStrengthen relevant filtering rules
Malware incidentReview web-filtering effectiveness
New threat intelligenceUpdate blocklists/categories
New business applicationReview access requirements
New office/locationExtend filtering coverage
Remote-work expansionReview remote filtering
New regulatory requirementReview web-use controls
Repeated policy violationsInvestigate and take corrective action
False-positive complaintsReview filtering rules
Major security incidentReassess web-filtering controls
New filtering providerAssess security configuration

Startup-Focused Quick Summary

Does every startup need an expensive web-filtering platform?

No.

The objective is not to purchase a particular security product.

The objective is to reduce the organization’s exposure to websites that create security risks.

A startup may use:

  • DNS filtering
  • Cloud security service
  • Firewall
  • Endpoint security
  • Secure Web Gateway
  • Browser security
  • SASE platform

depending on its size and risk.

Minimum startup implementation

A startup can begin with:

  1. Define acceptable Internet usage.
  2. Identify high-risk website categories.
  3. Implement suitable web/DNS filtering.
  4. Protect company-managed devices.
  5. Block known malicious/phishing destinations.
  6. Define an exception process.
  7. Monitor significant filtering events.
  8. Review rules periodically.
  9. Keep evidence of configuration and review.

Simple rule

Block known and high-risk threats by default, while allowing legitimate business access through controlled exceptions.

Don’t try to block the entire Internet.

The goal is risk reduction without unnecessarily disrupting business operations.


Example Web-Filtering Policy Matrix

Website CategoryDefault ActionBusiness Exception
MalwareBlockNo
PhishingBlockNo
Known malicious domainsBlockNo
Command-and-controlBlockNo
Suspicious downloadsRestrict/BlockSecurity approval
Adult contentBlockNormally no
GamblingBlockBusiness-dependent
File sharingRestrictBusiness justification
Social mediaAllow/RestrictBusiness-dependent
Cloud storageAllow/RestrictBusiness-dependent
Software downloadsRestrictBusiness justification
Security researchAllowAs required

The exact categories should be determined according to the organization’s business requirements, risk assessment, and applicable legal requirements.


Web-Filtering Implementation Checklist

Policy

  • Is acceptable Internet usage defined?
  • Are prohibited activities documented?
  • Are employees informed about the requirements?

Technology

  • Is web/DNS filtering implemented?
  • Are company-managed devices covered?
  • Are remote users covered where appropriate?
  • Are malicious destinations blocked?

Administration

  • Who manages filtering?
  • Who can modify rules?
  • Are administrative changes controlled?
  • Are exceptions approved?

Monitoring

  • Are important filtering events logged?
  • Are security events reviewed?
  • Are repeated violations investigated?

Review

  • Are filtering rules periodically reviewed?
  • Are exceptions reviewed?
  • Are false positives investigated?
  • Is filtering updated based on emerging threats?

A.8.23 Audit Evidence

An auditor may request evidence such as:

Policy documentation

  • Acceptable Use Policy
  • Internet Usage Policy
  • Web Filtering Standard
  • Endpoint Security Policy

Technical evidence

  • Web-filtering configuration
  • DNS filtering configuration
  • Firewall configuration
  • Secure Web Gateway configuration
  • Endpoint security configuration
  • Block/allow lists

Monitoring evidence

  • Web-filtering logs
  • Blocked request reports
  • Phishing detection records
  • Malware detection events
  • Security alerts

Exception evidence

  • Access requests
  • Business justification
  • Security approval
  • Exception register
  • Exception review

Review evidence

  • Filtering-rule review
  • Administrative change records
  • Security configuration review
  • Periodic management/security review

A.8.23 Audit Checklist

Audit QuestionEvidence
Is Internet/web usage governed by security requirements?Acceptable Use Policy
Are high-risk website categories identified?Web Filtering Standard
Is web filtering implemented?Configuration
Are known malicious/phishing sites blocked?Filtering Configuration
Are company-managed devices covered?Endpoint Configuration
Are remote users covered where appropriate?Cloud/Endpoint Configuration
Are filtering exceptions controlled?Exception Register
Are filtering events logged where appropriate?Logs
Are significant security events monitored?Monitoring Evidence
Are rules periodically reviewed?Review Records
Are administrative changes controlled?Change Records
Are filtering controls updated when risks change?Change/Threat Records

Common Mistakes

1. Having a policy but no technical control

Writing “employees must not visit malicious websites” is not the same as implementing web filtering.

Where appropriate, technical controls should support the policy.

2. Blocking everything

Overly aggressive filtering can interfere with legitimate business activities.

Filtering should be risk-based.

3. No remote-user coverage

Employees working remotely may still access company resources and should be protected according to the organization’s security requirements.

4. Uncontrolled allow lists

An exception created once can remain permanently.

Exceptions should have an owner, justification and appropriate review.

5. No monitoring

If filtering events are important to the organization’s risk profile, relevant events should be logged and monitored.

6. Ignoring false positives

Legitimate business websites may occasionally be blocked.

There should be a controlled process for requesting and approving exceptions.

7. Treating web filtering as the only security control

Web filtering is one layer of defense.

It should work alongside controls such as:

  • Endpoint protection
  • Secure authentication
  • Email security
  • Vulnerability management
  • Security awareness
  • Network security
  • Incident management

Practical Implementation Model

A practical A.8.23 implementation model is:

Identify Web Risks

↓

Define Acceptable Use

↓

Identify High-Risk Categories

↓

Implement Web/DNS Filtering

↓

Apply to Users & Devices

↓

Block/Restrict High-Risk Content

↓

Manage Exceptions

↓

Monitor

↓

Review

↓

Update Based on Threats


Policy vs. Technical Control vs. Evidence

ElementExample
PolicyUsers shall use Internet resources in accordance with information-security requirements.
Security RequirementKnown malicious and phishing destinations should be blocked.
Technical ControlDNS filtering blocks identified malicious domains.
ProcessEmployees request controlled exceptions where legitimate business access is required.
EvidenceConfiguration, logs, exception records and review reports.

This distinction is important during an ISO 27001 audit.

A written Acceptable Use Policy does not by itself demonstrate effective web filtering.

The organization should demonstrate the connection between:

Risk → Policy → Technical Control → Monitoring → Review


Useful Resources

Recommended documents

  • Draft Web Filtering Standard – [Insert Draft Document Link]
  • Acceptable Use Policy – [Insert Draft Document Link]
  • Internet Usage Policy – [Insert Draft Document Link]
  • Web Filtering Exception Request Form – [Insert Draft Document Link]
  • Web Filtering Review Checklist – [Insert Draft Document Link]
  • Endpoint Security Standard – [Insert Draft Document Link]
  • Security Awareness Guide – [Insert Draft Document Link]

Related ISO 27001 controls

A.8.23 works closely with:

  • A.5.10 – Acceptable use of information and other associated assets
  • A.5.15 – Access control
  • A.5.23 – Information security for use of cloud services
  • A.6.3 – Information security awareness, education and training
  • A.8.1 – User endpoint devices
  • A.8.7 – Protection against malware
  • A.8.14 – Redundancy of information processing facilities
  • A.8.15 – Logging
  • A.8.16 – Monitoring activities
  • A.8.20 – Network security
  • A.8.22 – Segregation of networks

Final Takeaway

ISO 27001 Annex A 8.23 is about controlling access to external websites to reduce information-security risks.

A practical organization should be able to answer:

What web risks have we identified?
Which websites or categories are restricted?
How is filtering implemented?
Who manages it?
How are exceptions handled?
How do we monitor and review the control?

For startups, implementation can be lightweight.

You do not necessarily need an expensive enterprise security platform. A suitable DNS filtering, endpoint, firewall, cloud security or Secure Web Gateway solution may provide the required capability depending on the organization’s risk.

The goal is not to control every website an employee visits.

The goal is to reduce exposure to websites that could compromise users, systems or information while allowing legitimate business activity.

A.8.23 = Identify → Filter → Block/Restrict → Manage Exceptions → Monitor → Review → Improve.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *