ISO 27001 Annex A 8.23 Web Filtering Explained

Stuart And Fay High Table

ISO 27001 Web Filtering

ISO 27001 Annex A 8.23 Web Filtering is an ISO 27001 control that requires us to manage access to external websites so that we can reduce the exposure we have to malicious and dangerous content.

ISO 27001 Annex A 8.23 Web Filtering

Key Takeaways

ISO 27001 Annex A 8.23 requires organizations to manage and restrict access to external websites to reduce exposure to malicious content. While often associated with productivity (e.g., blocking social media), the primary goal of this control in ISO 27001 is malware prevention, stopping users from accidentally visiting sites that host viruses, phishing scams, or illegal content.

Purpose

ISO 27001 Annex A 8.23 is a preventive control to protect systems from being compromised by malware and to prevent access to unauthorised web resources.

Definition

The ISO 27001 standard defines ISO 27001 Annex A 8.23 as:

Access to external websites should be managed to reduce exposure to malicious content.

ISO27001:2022 Annex A 8.23 Web Filtering

Requirement

  • Define the Rules: You must have a clear policy on “Acceptable Use” that defines what sites are off-limits (e.g., Gambling, Adult Content, Hacking Forums, File Sharing).
  • Technical Implementation: You cannot just “ask” users to be careful. You must implement technical controls such as DNS filtering, Firewall rules, or browser plugins to actively block access to known bad categories.
  • The “Exception” Process: Security cannot block business. You need a documented process for users to request access to a blocked site if they have a legitimate business reason (e.g., a Marketing Manager needing access to Facebook).
  • Communication: Users must be informed why filtering is in place. If they hit a block page, it should clearly state that the site was blocked for security reasons, not just to annoy them.

Audit Focus

  1. Evidence of Blocking: They might ask you to demonstrate what happens if a user tries to visit a known malicious URL (e.g., a test site).
  2. The Exception Log: “Show me the ticket where the HR team requested access to a blocked recruitment site.”
  3. No “Blanket” Blocks: They check that you aren’t over-blocking to the point of hindering business operations (availability).

Establish Rules

To implement this control you should establish what it is that you want people to do and be able to access. Putting time into establishing rules for the use of online resources, the acceptable use, and working out what is undesirable or inappropriate.

Communicate and Train

Once you know what your rules are and what you do and do not want people to be able to do, this should be communicated and training provided. As always as part of communicating, how to raise a concern would be included.

Exception Process

If you do put restrictions in place then it is important to have an exception process. This is a process that people can follow that will allow access to things otherwise restricted and will be a documented audit trail of approval and the actions taken. Often access is time based.

Web Filtering Techniques

When it comes to web filtering techniques there are many things that will factor into this ranging from the risk that you have, to the skills  and technology that you have and are comfortable with. Most small businesses don’t want to restrict and it can be quite a difficult thing to do if people use their own devices.

When implementing consider web filtering techniques that are built into software such as antivirus and the browser technology you have deployed. Consider the capabilities of your firewalls. Also to consider are off the shelf tools. Choose what is right for you.

Deciding what to filter

As mentioned already this is going to be based on risk and business need. There are categories in most web filtering solutions that can be turned on and make the job easier. These categories are straightforward and easy to understand. The areas that would be considered for restriction would be

  • Ilegal content
  • Command and control servers
  • Malicious websites
  • Sites with the ability to upload information

The following are further considerations from the standard to be considered.

Access to networks and services

For this we consider what can and should be accessed and then have appropriate policy and process in place around that access.

Authentication

The requirements on authentication for accessing services should be set.

Authorisation

Procedures that determine who is allowed to access networks and services are to be put in place.

Technical Controls

The network management and technical controls as well as the processes to access connections and services will be in place.

Access Types

How access is carried out such as physical network, wireless network, VPN will be determined.

Monitoring and Logging

Recording the time, location and other appropriate logging attributes of users that access networks and services will be in place.

Security Features

The security features of networks will be identified and implemented as well as documented. Consider here things like encryption, connection controls, cacheing, restrictive access. Firewalls, private networks, intrusion detection are also to be considered.

Network Security Professional

All in all you should work what a network security professional to work out the best solution for you and your needs. Your requirement is to identify, document, implement, monitor and review it.

Network Security Policy Template

ISO 27001 Network Security Management Policy Template - ISO 27001 Annex A 8.23 Web Filtering Template
ISO 27001 Network Security Policy Template

How to implement it

Implementing effective web filtering is essential for mitigating the risk of malware infections and preventing unauthorised access to malicious websites. By following these technical steps, your organisation can align with ISO 27001 Annex A 8.23 requirements and establish a proactive defence against web-based threats.

1. Formalise a Web Filtering Policy and Acceptable Use Policy (AUP)

  • Develop a formal policy that defines the categories of websites to be restricted, such as known malware hosts, phishing domains, and high-risk content.
  • Establish clear exceptions for specific business roles that require broader access, ensuring these are documented and reviewed regularly.
  • Result: A legally and operationally sound framework that sets clear expectations for employee browsing behaviour.

2. Provision a Secure Web Gateway (SWG) or DNS Filter

  • Deploy a cloud-based or on-premises Secure Web Gateway (SWG) to perform real-time URL categorisation and traffic inspection.
  • Implement DNS-level filtering to block malicious requests at the resolution stage, providing an additional layer of protection for remote and mobile devices.
  • Result: Automatic blocking of known threats before they can establish a connection with the internal network.

3. Enforce TLS Inspection and Decryption Standards

  • Configure the filtering solution to decrypt and inspect HTTPS traffic to identify hidden malware and data exfiltration attempts.
  • Establish a bypass list for sensitive traffic, such as banking or healthcare sites, to maintain user privacy and comply with data protection regulations.
  • Result: Visibility into encrypted traffic, which currently accounts for the vast majority of web-delivered threats.

4. Restrict Administrative Access via Granular IAM Roles

  • Apply the Principle of Least Privilege by assigning specific Identity and Access Management (IAM) roles to administrators managing filtering rules.
  • Mandate Multi-Factor Authentication (MFA) for all changes to the web filtering configuration to prevent unauthorised policy modifications.
  • Result: Protection against insider threats or account compromises that could lead to the bypass of critical security controls.

5. Execute Regular Rule Updates and Threat Intelligence Feeds

  • Automate the synchronisation of threat intelligence feeds to ensure the filtering engine is updated with the latest malicious domains and IP addresses.
  • Conduct periodic reviews of blocked categories to ensure they remain aligned with the organisation’s evolving risk profile and business needs.
  • Result: A dynamic defence system that remains effective against rapidly changing web-based attack vectors.

6. Implement Monitoring, Logging, and Incident Response

  • Integrate web filtering logs with a Security Information and Event Management (SIEM) system to detect patterns of attempted access to malicious sites.
  • Establish a formal incident response procedure for “High-Risk Block” events, including automated alerts for security personnel.
  • Result: Enhanced situational awareness and the ability to investigate potential infections before they escalate into major breaches.
CEO at High Table: The Compliance Agency

What an auditor will check

The audit is going to check a number of areas. Lets go through the main ones

1. That you have documentation

What this means is that you need to show that you have documented your web filtering implementation and processes and put in place an exception step as required.

2. That you have have implemented Web Filtering appropriately

They will look at systems to seek evidence of that it is implement appropriately. They will want to see evidence of the controls that in place and that they are operating. Allowlist or deny lists will be expected to be in place and evidenced.

3. That you have conducted internal audits

The audit will want to see that you have tested the controls and evidenced that they are operating. This is usually in the form of the required internal audits. They will check the records and outputs of those internal audits.

Applicability across different business models

Business TypeApplicabilityExamples of Control Implementation
Small BusinessesFocuses on using simple, automated tools to block high-risk categories (e.g., gambling, adult content) that often host malware. The goal is “set and forget” protection for general staff.
  • Configuring the office router or using a DNS filter (e.g., OpenDNS) to block known malicious domains automatically.
  • Enabling “Safe Browsing” features in the company antivirus software on all laptops.
  • Blocking access to file-sharing sites to prevent accidental data leakage or downloading pirated software.
Tech StartupsRequires a balanced approach. While blocking malware is critical, developers often need access to obscure forums or code repositories. An efficient “Exception Process” is key here.
  • Implementing “Category Filtering” to block “Hacking” and “Malware” sites but allowing “Technology” and “Developer Tools”.
  • Creating a streamlined Slack channel or ticket workflow for developers to request immediate unblocking of legitimate sites.
  • Using endpoint-based filtering agents that work even when developers are working remotely (Wfh).
AI CompaniesCritical for preventing data exfiltration. Filtering is used to stop employees from uploading sensitive training data to unauthorized public AI tools or cloud storage.
  • Blocking access to public “Pastebin” sites and unauthorized GenAI platforms to prevent model leakage.
  • Using TLS inspection to detect and block connections to known “Command and Control” (C2) servers.
  • Whitelisting only approved cloud storage providers for uploading large datasets, blocking all others.

FAQ

Is web filtering mandatory for ISO 27001 compliance?

Yes, managing access to external websites is a required control to reduce exposure to malicious content. While the standard does not mandate specific software, you must demonstrate that you have technical measures and policies in place to control which websites users can access on your network.
Policy: You must have a documented Acceptable Use Policy.
Enforcement: You must use technical tools (firewalls, DNS filters) to enforce rules.
Evidence: You must provide logs showing that restrictions are active.

Does ISO 27001 require blocking social media sites?

No, ISO 27001 does not explicitly require blocking social media or news sites unless they pose a specific security risk to your organization. The decision to block productivity-related categories is a business choice, whereas blocking malicious categories (like hacking forums or malware sites) is a security necessity.
Risk Assessment: Blocking should be based on your specific risk appetite.
Business Needs: Marketing teams often require social media access.
Focus: Prioritise blocking “High Risk” categories over “Productivity” categories.

What are the best web filtering strategies for this control?

The most effective strategies are Category Filtering and Block Listing, as they balance security with usability. Auditors typically look for a layered approach that stops threats without preventing legitimate work.
Category Filtering: Blocking entire groups of sites (e.g., “Adult,” “Gambling,” “P2P”).
Block Listing (Blacklisting): Specifically denying access to known malicious URLs.
Allow Listing (Whitelisting): Blocking everything except approved sites (High security, but high maintenance).

How should legitimate requests for blocked sites be handled?

You must implement a formal Exception Management Process that allows staff to request access to blocked sites for valid business reasons. This ensures that security controls do not hinder business operations and provides an audit trail of approved exceptions.
Submission: User submits a ticket explaining the business need.
Review: Security team scans the site for actual threats.
Approval: Access is granted temporarily or permanently if safe.
Logging: The approval is documented for the auditor.

What evidence will an auditor ask for regarding web filtering?

Auditors will request your Acceptable Use Policy, configuration screenshots of your filtering tools, and logs showing blocked attempts. They want to see proof that the rules defined in your policy are actually implemented in your technology.
Policy Document: clearly defining prohibited website categories.
System Configs: Screenshots of DNS or Firewall rules.
Incident Logs: Reports showing the system successfully blocked a user.
Exception Records: Documentation of authorized bypasses.

Further Reading

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 8.23 Web Filtering
Shopping Basket
Scroll to Top