Skip to content
compliancebase
ISO 27001A.8 — Web filtering

A.8.23

Web filtering

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Manage access to external websites to reduce exposure to malicious content and unauthorized services.

Points of focus

  • Define acceptable-use and category policy with an owner
  • Enforce filtering on managed endpoints and corporate networks
  • Document override/break-glass for business need
  • Review categories after incidents or tool changes

Implementation notes

Deploy DNS filtering or a secure web gateway through MDM for all devices that authenticate to the IdP or reach admin consoles. Publish category rationale (malware, newly registered domains, file sharing, anonymizers) and a security-approved override path with time limits. Log blocks at aggregate level for tuning — do not rely on filtering alone for data exfiltration (see A.8.12 DLP themes). Revisit categories after phishing incidents or when browser isolation is introduced as an alternative control.

Audit tip: Show enforced policy on a sample laptop and the named owner who reviews categories quarterly. If fully browser-isolated for admin tasks, document equivalency in the SoA.

Evidence auditors typically request:

  • DNS/SWG policy export with category lists
  • MDM compliance report showing filtering enabled
  • Override ticket samples with approver and duration
  • Quarterly category review minutes

Common gaps

  • Remote laptops off MDM bypass filtering entirely
  • Aggressive blocks push engineers to personal devices for downloads
  • Category lists stale after acquiring a new SaaS tool

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.23This control
SOC 2CC6.6, CC6.8Related SOC 2 themes (CC6.6, CC6.8) — map in your crosswalk; not identical requirements.
GDPRArticle 32Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements.
HIPAA§164.308(a)(5)Related HIPAA themes (§164.308(a)(5)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Yes for endpoints that store session tokens or run agents — drive-by and malicious redirects still target browsers. Intensity is risk-based.

It can be an alternative if documented in the SoA with equivalent malware reduction — do not claim both without need.

Filtering reduces malicious sites; A.6.3/A.8.23 complement MFA and awareness for credential phishing.

Either block production access from unmanaged devices or require MDM enrollment — filtering without device management fails quickly.

CC6.6/CC6.8 logical access and malware protection themes — cite your crosswalk, not identity of requirements.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above