A.8.23
Web filtering
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Manage access to external websites to reduce exposure to malicious content and unauthorized services.
Points of focus
- Define acceptable-use and category policy with an owner
- Enforce filtering on managed endpoints and corporate networks
- Document override/break-glass for business need
- Review categories after incidents or tool changes
Implementation notes
Deploy DNS filtering or a secure web gateway through MDM for all devices that authenticate to the IdP or reach admin consoles. Publish category rationale (malware, newly registered domains, file sharing, anonymizers) and a security-approved override path with time limits. Log blocks at aggregate level for tuning — do not rely on filtering alone for data exfiltration (see A.8.12 DLP themes). Revisit categories after phishing incidents or when browser isolation is introduced as an alternative control.
Audit tip: Show enforced policy on a sample laptop and the named owner who reviews categories quarterly. If fully browser-isolated for admin tasks, document equivalency in the SoA.
Evidence auditors typically request:
- DNS/SWG policy export with category lists
- MDM compliance report showing filtering enabled
- Override ticket samples with approver and duration
- Quarterly category review minutes
Common gaps
- Remote laptops off MDM bypass filtering entirely
- Aggressive blocks push engineers to personal devices for downloads
- Category lists stale after acquiring a new SaaS tool
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.23 | This control |
| SOC 2 | CC6.6, CC6.8 | Related SOC 2 themes (CC6.6, CC6.8) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.308(a)(5) | Related HIPAA themes (§164.308(a)(5)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.23)