Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.23

Web Filtering: A Practical Implementation Guide

Reduce exposure to malicious and inappropriate web resources while preserving legitimate business use.

This control concerns managing access to external websites to reduce exposure to malicious content.

Practical interpretation: Filtering should combine threat intelligence, categories, DNS or proxy controls, encrypted-traffic considerations, exceptions and user reporting.

What should the control achieve?

  • Web risk and acceptable-use objectives are defined.
  • Known malicious destinations are blocked quickly.
  • Category controls are proportionate and lawful.
  • Exceptions and bypass attempts are monitored.

Step-by-step implementation

1

Define objectives

Prioritize malware, phishing, command-and-control, newly registered domains and prohibited categories.

2

Choose enforcement points

Use DNS, secure web gateway, endpoint, browser or cloud controls.

3

Integrate intelligence

Consume reputable block lists and rapid incident indicators.

4

Handle encrypted traffic

Decide inspection scope with privacy, certificate and technical risk review.

5

Manage exceptions

Require business reason, owner, duration and monitoring.

6

Measure and tune

Review blocks, false positives, bypass and infection outcomes.

What this could look like in practice

Managed endpoints use protective DNS and a secure web gateway. Confirmed phishing domains are blocked immediately. Business exceptions expire after 30 days and personal privacy-sensitive categories are not inspected unnecessarily.

ActivityPractical implementationEvidence
Malicious domainThreat feed blocks access globally.Gateway log
Category rulePolicy restricts known high-risk download sites.Configuration
ExceptionManager and Security approve temporary access.Exception record
User reportReported site is investigated and blocked if malicious.Ticket

Implementation evidence

  • Web-filtering policy
  • Category decisions
  • DNS or gateway configuration
  • Threat-feed integration
  • Privacy assessment
  • Exception register
  • Block logs
  • Tuning reviews

Useful metrics

  • Malicious requests blocked
  • Confirmed false positives
  • Expired exceptions
  • Web-origin malware incidents

Common mistakes

  • Treating filtering as a substitute for endpoint protection.
  • Blocking without business exception process.
  • Inspecting sensitive traffic without review.
  • Ignoring unmanaged browsers and remote devices.
  • Never tuning categories.

Questions an auditor may ask

  • Which web risks are prioritized?
  • Where is filtering enforced?
  • How are exceptions approved?
  • How is privacy considered?
Implementation test: Use safe test destinations to verify malicious, category, exception and remote-device behavior and logging.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.