ISO/IEC 27001:2022 Annex A · Control 8.23
Web Filtering: A Practical Implementation Guide
Reduce exposure to malicious and inappropriate web resources while preserving legitimate business use.
This control concerns managing access to external websites to reduce exposure to malicious content.
What should the control achieve?
- Web risk and acceptable-use objectives are defined.
- Known malicious destinations are blocked quickly.
- Category controls are proportionate and lawful.
- Exceptions and bypass attempts are monitored.
Step-by-step implementation
Define objectives
Prioritize malware, phishing, command-and-control, newly registered domains and prohibited categories.
Choose enforcement points
Use DNS, secure web gateway, endpoint, browser or cloud controls.
Integrate intelligence
Consume reputable block lists and rapid incident indicators.
Handle encrypted traffic
Decide inspection scope with privacy, certificate and technical risk review.
Manage exceptions
Require business reason, owner, duration and monitoring.
Measure and tune
Review blocks, false positives, bypass and infection outcomes.
What this could look like in practice
Managed endpoints use protective DNS and a secure web gateway. Confirmed phishing domains are blocked immediately. Business exceptions expire after 30 days and personal privacy-sensitive categories are not inspected unnecessarily.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Malicious domain | Threat feed blocks access globally. | Gateway log |
| Category rule | Policy restricts known high-risk download sites. | Configuration |
| Exception | Manager and Security approve temporary access. | Exception record |
| User report | Reported site is investigated and blocked if malicious. | Ticket |
Implementation evidence
- Web-filtering policy
- Category decisions
- DNS or gateway configuration
- Threat-feed integration
- Privacy assessment
- Exception register
- Block logs
- Tuning reviews
Useful metrics
- Malicious requests blocked
- Confirmed false positives
- Expired exceptions
- Web-origin malware incidents
Common mistakes
- Treating filtering as a substitute for endpoint protection.
- Blocking without business exception process.
- Inspecting sensitive traffic without review.
- Ignoring unmanaged browsers and remote devices.
- Never tuning categories.
Questions an auditor may ask
- Which web risks are prioritized?
- Where is filtering enforced?
- How are exceptions approved?
- How is privacy considered?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.