Web filtering
Purpose
Manage access to external websites to cut exposure to malicious content and block unauthorised web resources.
How to meet this control
In short: Manage access to external websites to reduce exposure to malicious content.
- Step 01Deploy DNS or web filtering (Cisco Umbrella, Cloudflare Gateway, a secure web gateway) to block known-malicious and phishing domains
- Step 02Define and maintain category-based blocking aligned to acceptable use, for example malware, anonymisers and unsanctioned file-sharing
- Step 03Keep block lists current using threat intelligence and the provider reputation feeds
- Step 04Consider restricting upload-capable sites unless there is a business justification, to reduce data leakage
- Step 05Extend filtering to remote and roaming devices through an agent so protection follows the user off the office network
- Step 06Train staff on the rules, the exception process and not overriding browser security warnings
Tip: DNS/web filtering blocking known-malicious categories.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Reduce the chance of staff reaching sites known to host malware or phishing
- ›Block access by IP address or domain using browser or anti-malware features
- ›Identify which categories of website staff should and should not reach
- ›Consider blocking sites with upload functions unless there is a valid business reason
- ›Use threat intelligence to keep the list of blocked malicious sites current
- ›Set and maintain rules for safe use of online resources before turning the control on
- ›Train staff on the rules, who to contact and how to request exceptions
- ›Train staff not to override browser warnings that flag a site as insecure
Audit evidence to keep
- - Web filtering policy and category block configuration
- - Sample log of a blocked malicious or phishing domain
- - Evidence threat intelligence keeps block lists current
- - Configuration showing filtering applies to roaming or remote devices
- - Awareness material covering safe browsing and exceptions
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.23. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.