What is ISO 27001 Annex A 8.23 – Web Filtering?
ISO 27001 Annex A 8.23 focuses on managing access to external websites to reduce exposure to malicious or inappropriate online content.
Organizations should manage access to external websites to protect users and information systems from risks such as:
- Malware
- Phishing
- Malicious downloads
- Command-and-control infrastructure
- Fraudulent websites
- Unauthorized software
- Inappropriate content
- Websites presenting significant security risks
Simple explanation
A.8.23 means the organization should control or manage access to websites that may create information-security risks.
This does not necessarily mean blocking large numbers of websites.
The organization should implement web filtering based on its security risks, business requirements, and acceptable-use rules.
Why is Web Filtering Important?
Employees frequently access the Internet for:
- Research
- Business applications
- Cloud services
- Social media
- File sharing
- Software downloads
- Collaboration
- Customer support
Uncontrolled web access can expose the organization to:
- Phishing attacks
- Malware
- Drive-by downloads
- Credential theft
- Malicious advertisements
- Data leakage
- Access to known malicious domains
- Unauthorized applications
- Security-policy violations
For example:
Employee receives phishing email
↓
Clicks malicious link
↓
Malicious website
↓
Credential theft / malware
Web filtering can provide an additional layer of protection by blocking known malicious or inappropriate destinations.
What does A.8.23 require?
The organization should determine whether web access needs to be controlled and implement appropriate filtering mechanisms based on its risks.
The organization should consider:
- Types of websites that create security risks
- Categories that should be blocked
- How exceptions are managed
- Who can change filtering rules
- How filtering is monitored
- How blocked requests are handled
- How filtering effectiveness is reviewed
The control should be implemented in a way that supports legitimate business activities.
Activities Required to Implement A.8.23
1. Establish acceptable web-use requirements
Define how organizational systems and devices may be used to access external websites.
This may be documented in:
- Acceptable Use Policy
- Information Security Policy
- Internet Usage Policy
- Endpoint Security Standard
The policy should explain acceptable and prohibited activities.
2. Identify risky website categories
Organizations can use categories to manage web access.
Examples include:
| Category | Example Treatment |
|---|---|
| Known malicious sites | Block |
| Phishing sites | Block |
| Malware distribution | Block |
| Command-and-control sites | Block |
| Illegal content | Block where appropriate |
| High-risk downloads | Restrict |
| Newly registered/suspicious domains | Consider blocking/restricting |
| Adult content | Block according to policy |
| Gambling | Block according to policy |
| Social media | Business-dependent |
| File-sharing services | Business-dependent |
| Streaming | Business-dependent |
| Personal email | Business-dependent |
The categories should be appropriate for the organization’s business and legal environment.
3. Implement web-filtering technology
Web filtering can be implemented through:
- Secure Web Gateways
- DNS filtering
- Web proxies
- Firewall filtering
- Cloud-based security services
- Endpoint security solutions
- Browser security controls
- Secure Access Service Edge (SASE) solutions
- Cloud access security solutions
A startup does not necessarily need an expensive enterprise Secure Web Gateway.
A suitable cloud-based DNS or endpoint filtering solution may be sufficient depending on risk.
4. Apply filtering to relevant users and devices
Determine which devices should be covered.
For example:
- Company laptops
- Company desktops
- Corporate mobile devices
- Virtual desktops
- Remote employee devices
- Servers, where applicable
Remote employees should not automatically be excluded simply because they are working outside the office.
5. Configure block and allow rules
The organization should define:
Block
Known malicious and high-risk destinations.
Allow
Websites required for legitimate business activities where necessary.
Exception
A controlled process for legitimate websites that are incorrectly blocked.
For example:
Employee requests access
↓
Business justification
↓
Security review
↓
Approval
↓
Temporary/permanent exception
↓
Document decision
6. Protect against malicious websites
Filtering should help identify or block threats such as:
- Phishing domains
- Malware sites
- Malicious downloads
- Botnet infrastructure
- Command-and-control destinations
- Known fraudulent websites
Where available, threat-intelligence feeds can improve filtering effectiveness.
7. Monitor web-filtering events
Depending on risk and privacy requirements, the organization may monitor:
- Blocked requests
- Malware detections
- Phishing attempts
- High-risk website access
- Policy violations
- Filtering exceptions
- Administrative changes
Monitoring should comply with applicable privacy, employment and legal requirements.
8. Review filtering rules
Filtering rules should be reviewed periodically and after significant events.
Review:
- Blocked categories
- Allow lists
- Exceptions
- Administrative changes
- Security events
- False positives
- Business requirements
Remove unnecessary exceptions.
Example – SaaS Startup
Consider a SaaS company with 50 employees working from different locations.
Employees use:
- Company laptops
- Microsoft 365
- GitHub
- AWS
- Slack
- Browser-based business applications
The company implements cloud-based DNS/web filtering.
Security policy
The organization blocks:
- Known malicious websites
- Phishing domains
- Malware distribution sites
- Command-and-control destinations
- Other high-risk categories defined by policy
Employees can access normal business websites.
If a legitimate website is blocked:
Employee submits request
↓
Business justification
↓
Security review
↓
Approval
↓
Exception recorded
The organization reviews filtering events periodically.
This gives the company a practical web-filtering control without requiring a large on-premises security infrastructure.
What Events Should Trigger Action or Review?
| Trigger | Possible Action |
|---|---|
| Phishing campaign | Strengthen relevant filtering rules |
| Malware incident | Review web-filtering effectiveness |
| New threat intelligence | Update blocklists/categories |
| New business application | Review access requirements |
| New office/location | Extend filtering coverage |
| Remote-work expansion | Review remote filtering |
| New regulatory requirement | Review web-use controls |
| Repeated policy violations | Investigate and take corrective action |
| False-positive complaints | Review filtering rules |
| Major security incident | Reassess web-filtering controls |
| New filtering provider | Assess security configuration |
Startup-Focused Quick Summary
Does every startup need an expensive web-filtering platform?
No.
The objective is not to purchase a particular security product.
The objective is to reduce the organization’s exposure to websites that create security risks.
A startup may use:
- DNS filtering
- Cloud security service
- Firewall
- Endpoint security
- Secure Web Gateway
- Browser security
- SASE platform
depending on its size and risk.
Minimum startup implementation
A startup can begin with:
- Define acceptable Internet usage.
- Identify high-risk website categories.
- Implement suitable web/DNS filtering.
- Protect company-managed devices.
- Block known malicious/phishing destinations.
- Define an exception process.
- Monitor significant filtering events.
- Review rules periodically.
- Keep evidence of configuration and review.
Simple rule
Block known and high-risk threats by default, while allowing legitimate business access through controlled exceptions.
Don’t try to block the entire Internet.
The goal is risk reduction without unnecessarily disrupting business operations.
Example Web-Filtering Policy Matrix
| Website Category | Default Action | Business Exception |
|---|---|---|
| Malware | Block | No |
| Phishing | Block | No |
| Known malicious domains | Block | No |
| Command-and-control | Block | No |
| Suspicious downloads | Restrict/Block | Security approval |
| Adult content | Block | Normally no |
| Gambling | Block | Business-dependent |
| File sharing | Restrict | Business justification |
| Social media | Allow/Restrict | Business-dependent |
| Cloud storage | Allow/Restrict | Business-dependent |
| Software downloads | Restrict | Business justification |
| Security research | Allow | As required |
The exact categories should be determined according to the organization’s business requirements, risk assessment, and applicable legal requirements.
Web-Filtering Implementation Checklist
Policy
- Is acceptable Internet usage defined?
- Are prohibited activities documented?
- Are employees informed about the requirements?
Technology
- Is web/DNS filtering implemented?
- Are company-managed devices covered?
- Are remote users covered where appropriate?
- Are malicious destinations blocked?
Administration
- Who manages filtering?
- Who can modify rules?
- Are administrative changes controlled?
- Are exceptions approved?
Monitoring
- Are important filtering events logged?
- Are security events reviewed?
- Are repeated violations investigated?
Review
- Are filtering rules periodically reviewed?
- Are exceptions reviewed?
- Are false positives investigated?
- Is filtering updated based on emerging threats?
A.8.23 Audit Evidence
An auditor may request evidence such as:
Policy documentation
- Acceptable Use Policy
- Internet Usage Policy
- Web Filtering Standard
- Endpoint Security Policy
Technical evidence
- Web-filtering configuration
- DNS filtering configuration
- Firewall configuration
- Secure Web Gateway configuration
- Endpoint security configuration
- Block/allow lists
Monitoring evidence
- Web-filtering logs
- Blocked request reports
- Phishing detection records
- Malware detection events
- Security alerts
Exception evidence
- Access requests
- Business justification
- Security approval
- Exception register
- Exception review
Review evidence
- Filtering-rule review
- Administrative change records
- Security configuration review
- Periodic management/security review
A.8.23 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Is Internet/web usage governed by security requirements? | Acceptable Use Policy |
| Are high-risk website categories identified? | Web Filtering Standard |
| Is web filtering implemented? | Configuration |
| Are known malicious/phishing sites blocked? | Filtering Configuration |
| Are company-managed devices covered? | Endpoint Configuration |
| Are remote users covered where appropriate? | Cloud/Endpoint Configuration |
| Are filtering exceptions controlled? | Exception Register |
| Are filtering events logged where appropriate? | Logs |
| Are significant security events monitored? | Monitoring Evidence |
| Are rules periodically reviewed? | Review Records |
| Are administrative changes controlled? | Change Records |
| Are filtering controls updated when risks change? | Change/Threat Records |
Common Mistakes
1. Having a policy but no technical control
Writing “employees must not visit malicious websites” is not the same as implementing web filtering.
Where appropriate, technical controls should support the policy.
2. Blocking everything
Overly aggressive filtering can interfere with legitimate business activities.
Filtering should be risk-based.
3. No remote-user coverage
Employees working remotely may still access company resources and should be protected according to the organization’s security requirements.
4. Uncontrolled allow lists
An exception created once can remain permanently.
Exceptions should have an owner, justification and appropriate review.
5. No monitoring
If filtering events are important to the organization’s risk profile, relevant events should be logged and monitored.
6. Ignoring false positives
Legitimate business websites may occasionally be blocked.
There should be a controlled process for requesting and approving exceptions.
7. Treating web filtering as the only security control
Web filtering is one layer of defense.
It should work alongside controls such as:
- Endpoint protection
- Secure authentication
- Email security
- Vulnerability management
- Security awareness
- Network security
- Incident management
Practical Implementation Model
A practical A.8.23 implementation model is:
Identify Web Risks
↓
Define Acceptable Use
↓
Identify High-Risk Categories
↓
Implement Web/DNS Filtering
↓
Apply to Users & Devices
↓
Block/Restrict High-Risk Content
↓
Manage Exceptions
↓
Monitor
↓
Review
↓
Update Based on Threats
Policy vs. Technical Control vs. Evidence
| Element | Example |
|---|---|
| Policy | Users shall use Internet resources in accordance with information-security requirements. |
| Security Requirement | Known malicious and phishing destinations should be blocked. |
| Technical Control | DNS filtering blocks identified malicious domains. |
| Process | Employees request controlled exceptions where legitimate business access is required. |
| Evidence | Configuration, logs, exception records and review reports. |
This distinction is important during an ISO 27001 audit.
A written Acceptable Use Policy does not by itself demonstrate effective web filtering.
The organization should demonstrate the connection between:
Risk → Policy → Technical Control → Monitoring → Review
Useful Resources
Recommended documents
- Draft Web Filtering Standard – [Insert Draft Document Link]
- Acceptable Use Policy – [Insert Draft Document Link]
- Internet Usage Policy – [Insert Draft Document Link]
- Web Filtering Exception Request Form – [Insert Draft Document Link]
- Web Filtering Review Checklist – [Insert Draft Document Link]
- Endpoint Security Standard – [Insert Draft Document Link]
- Security Awareness Guide – [Insert Draft Document Link]
Related ISO 27001 controls
A.8.23 works closely with:
- A.5.10 – Acceptable use of information and other associated assets
- A.5.15 – Access control
- A.5.23 – Information security for use of cloud services
- A.6.3 – Information security awareness, education and training
- A.8.1 – User endpoint devices
- A.8.7 – Protection against malware
- A.8.14 – Redundancy of information processing facilities
- A.8.15 – Logging
- A.8.16 – Monitoring activities
- A.8.20 – Network security
- A.8.22 – Segregation of networks
Final Takeaway
ISO 27001 Annex A 8.23 is about controlling access to external websites to reduce information-security risks.
A practical organization should be able to answer:
What web risks have we identified?
Which websites or categories are restricted?
How is filtering implemented?
Who manages it?
How are exceptions handled?
How do we monitor and review the control?
For startups, implementation can be lightweight.
You do not necessarily need an expensive enterprise security platform. A suitable DNS filtering, endpoint, firewall, cloud security or Secure Web Gateway solution may provide the required capability depending on the organization’s risk.
The goal is not to control every website an employee visits.
The goal is to reduce exposure to websites that could compromise users, systems or information while allowing legitimate business activity.
A.8.23 = Identify → Filter → Block/Restrict → Manage Exceptions → Monitor → Review → Improve.
