A.8.23New in 2022A.8 Technological controls

Web filtering

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.23 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Manage access to external websites to cut exposure to malicious content and block unauthorised web resources.

How to meet this control

In short: Manage access to external websites to reduce exposure to malicious content.

  1. Step 01Deploy DNS or web filtering (Cisco Umbrella, Cloudflare Gateway, a secure web gateway) to block known-malicious and phishing domains
  2. Step 02Define and maintain category-based blocking aligned to acceptable use, for example malware, anonymisers and unsanctioned file-sharing
  3. Step 03Keep block lists current using threat intelligence and the provider reputation feeds
  4. Step 04Consider restricting upload-capable sites unless there is a business justification, to reduce data leakage
  5. Step 05Extend filtering to remote and roaming devices through an agent so protection follows the user off the office network
  6. Step 06Train staff on the rules, the exception process and not overriding browser security warnings

Tip: DNS/web filtering blocking known-malicious categories.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Reduce the chance of staff reaching sites known to host malware or phishing
  • ›Block access by IP address or domain using browser or anti-malware features
  • ›Identify which categories of website staff should and should not reach
  • ›Consider blocking sites with upload functions unless there is a valid business reason
  • ›Use threat intelligence to keep the list of blocked malicious sites current
  • ›Set and maintain rules for safe use of online resources before turning the control on
  • ›Train staff on the rules, who to contact and how to request exceptions
  • ›Train staff not to override browser warnings that flag a site as insecure

Audit evidence to keep

  • - Web filtering policy and category block configuration
  • - Sample log of a blocked malicious or phishing domain
  • - Evidence threat intelligence keeps block lists current
  • - Configuration showing filtering applies to roaming or remote devices
  • - Awareness material covering safe browsing and exceptions

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.8.23. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.