ISO 27001 Web Filtering Explained – Annex A 8.23

Stuart Barker -271

ISO 27001 Annex A 8.23 Web Filtering sets clear rules for restricting access to risky or harmful websites. Managing web filters in everyday business tools helps protect organisations from malicious software and unsafe content.

Key Takeaways

  • Establish Web Filtering Policy: Define explicit rules, domain block categories, and acceptable use guidelines for internet browsing in a central SharePoint document.
  • Deploy Web Content Filtering: Implement automated DNS filtering, secure web gateways, or endpoint controls to block access to known malicious and inappropriate websites.
  • Document Approved Site Exceptions: Maintain a structured list of pre-approved business domains and whitelist request workflows in Confluence.
  • Build Web Access Change Workflows: Route all requests for domain unblocking or temporary filtering bypasses through formal Jira approval tickets.
  • Enforce Malware and Phishing Protections: Configure gateway controls to actively block access to high-risk domains, uncategorized sites, and suspected phishing links.
  • Log and Monitor Web Traffic: Centralize web filtering and gateway access logs to detect potential malware downloads, data exfiltration attempts, or policy violations.
  • Review Filtering Rules Regularly: Audit active blocklists and whitelist exceptions quarterly to ensure protection rules remain aligned with business risks.
  • Maintain Management Oversight: Record periodic web security metrics, policy compliance reviews, and exception sign-offs in management meeting minutes.

How to Implement ISO 27001 Annex A 8.23

  • Draft Acceptable Web Usage Policy: Document explicit guidelines in SharePoint defining blocked website categories, allowed business browsing, and mandatory internet safety rules.
  • Obtain Management Sign-off: Secure formal leadership approval using SharePoint version control and approval workflows to establish compliance governance.
  • Establish Exception Workflows: Configure a dedicated Jira project to log, review, and track user requests for access to blocked website categories or specific domains.
  • Mandate Business Justifications: Ensure every web access exception ticket in Jira requires a documented business reason, security review, and line manager sign-off.
  • Align Gateway Rulesets: Configure secure web gateways, DNS filtering controls, and endpoint agent rules to match the approved SharePoint policy categories.
  • Document Monthly Traffic Reviews: Examine web filtering logs and threat reports monthly, capturing management oversight notes in Confluence or meeting minutes.
  • Maintain Dynamic Blocklists: Update web filtering category rules dynamically to block high-risk domains, uncategorized sites, and newly discovered phishing links via formal change tickets.
  • Automate Policy Deployment: Push web filtering policies to all corporate endpoints via centralized device management tools to ensure protection for remote and mobile workers.

How to Audit ISO 27001 Annex A 8.23

  • Inspect Web Filtering Policies: Review the web filtering policy in SharePoint to confirm rules governing blocked website categories, allowed exceptions, and downloading controls are active and approved.
  • Verify Secure Web Gateway Settings: Inspect configurations on DNS firewalls, cloud web proxies, and endpoint agents to verify malicious and high-risk domain categories are actively blocked.
  • Sample Web Filtering Exception Requests: Audit recent Jira ticket records for temporary web access overrides to verify management approval and valid business justifications were documented.
  • Test Endpoint Protection Controls: Attempt to navigate to safe test domains or simulated malicious categories on a sample device to verify browser protection blocks illegal and dangerous content.
  • Audit Encrypted Traffic Inspection: Verify that TLS/SSL decryption policies are enabled on security gateways to scan encrypted web traffic for malicious payloads and file transfers.
  • Check Central Web Gateway Logs: Review sample log streams from web proxies and DNS tools to verify outbound web requests, blocked domains, and user details are recorded accurately.
  • Examine Periodic Category Reviews: Check meeting records and security review logs in internal wikis to confirm blocked domain categories, threat intelligence feeds, and exception lists are revalidated regularly.
  • Inspect Unapproved Web Upload Controls: Test Data Loss Prevention (DLP) controls on web proxies to ensure unauthorized uploads of sensitive files to personal cloud storage or unapproved SaaS sites are blocked.
  • Verify Coverage for Remote and Off-Grid Workers: Sample corporate laptops operating off the internal corporate network to confirm DNS filtering agents or cloud proxies remain actively enforced.
  • Audit Whitelist Maintenance: Sample current whitelist entries in web filtering gateways to ensure expired business exception requests have been purged in accordance with ticket durations.

Audit Evidence Checklist

  • Web Usage Policy: Provide the approved, version-controlled master Web Usage Policy stored in SharePoint detailing blocked domain categories and acceptable use rules.
  • Whitelist Exception History: Supply full Jira ticket logs showing requested domain overrides, documented business justifications, and technical reviews.
  • Management Exception Approvals: Present formal sign-offs and leadership authorizations recorded in SharePoint or Jira for specific high-risk category exceptions.
  • Web Security Review Minutes: Produce formal management meeting notes in Confluence documenting routine performance evaluations, web threat reviews, and policy compliance discussions.
  • Internal Filtering Audit Reports: Share internal audit findings and technical configuration checks verifying that active web gateway rules match approved policy standards.
  • Gateway Configuration Records: Provide exported rule logs from DNS filtering tools or cloud proxies demonstrating active blocking of malicious, phishing, and uncategorized sites.
  • Remote Endpoint Coverage Logs: Supply technical reports proving endpoint web filtering agents remain active and enforced on mobile and remote employee laptops.

What to Teach Employees

  • Understand Web Filtering Purpose: Teach employees why web filtering controls are implemented to block malicious sites, prevent malware downloads, and stop phishing attacks.
  • Recognize Blocked Categories: Show staff which website categories (e.g., gambling, adult, unapproved file-sharing, illegal content) are restricted under company acceptable use policies.
  • Request Category Overrides Safely: Train staff to use official Jira support ticket channels when requesting legitimate business access to blocked web pages or research domains.
  • Avoid Unapproved File Uploads: Remind employees never to upload confidential company files or sensitive customer data to unauthorized personal cloud storage or public AI tools.
  • Beware of Malicious Downloads: Train workers to inspect file source URLs before downloading executable files or software scripts from external web pages.
  • Do Not Bypass Web Proxies: Explain why using personal VPNs, proxy extensions, or mobile hotspots to bypass corporate web filtering violates security policy.
  • Identify Web Browser Warnings: Teach users how to respond correctly when browsers display security certificates or phishing warnings instead of ignoring the alerts.
  • Report Suspicious Web Redirects: Train employees to report unexpected pop-up windows, browser lockups, or automatic downloads to the security team immediately.
  • Respect Remote Web Security: Ensure remote employees know that corporate web filtering policies remain active on company laptops regardless of their location or network connection.

Common Implementation Challenges

  • False Positives Impacting Productivity: Overly strict web filtering policies frequently block legitimate research, marketing, or technical documentation sites, leading to user frustration and high IT ticket volumes.
  • Bypassing Controls via Shadow IT: Staff using mobile hotspots, browser proxy extensions, or personal VPNs to circumvent corporate web gateways and access restricted sites.
  • SSL/TLS Inspection Overhead: Decrypting and inspecting encrypted HTTPS web traffic for malicious payloads can introduce latency, break certificate pinning in specialized apps, or trigger privacy concerns.
  • Dynamic and Newly Registered Domains: Attackers continuously spin up short-lived malicious domains that threat intelligence feeds have not yet categorized, allowing phishing sites to temporarily evade filters.
  • Uncontrolled Data Leaks to Public AI Tools: Employees uploading proprietary code or sensitive company data to public AI writing assistants and cloud translation tools that fall outside standard category blocks.
  • Remote and Off-Network Endpoint Coverage: Ensuring cloud web gateway agents remain active and enforce filtering rules consistently on roaming employee laptops outside the corporate perimeter.
  • Managing Exception Accumulation: Temporary domain overrides and whitelist exceptions granted for short-term projects are rarely reviewed or removed, creating long-term security blind spots.
  • Miscategorization by Web Filter Vendors: Reliance on third-party URL classification databases that mislabel safe business sites or lag in identifying newly compromised legitimate websites.

How to Measure Effectiveness (KPIs)

  • Blocked Malicious Web Request Count: Tracks the volume of outbound connection attempts to malicious, phishing, or malware-hosting domains blocked by web filters.
  • Unapproved Web Upload Block Rate: Measures the percentage of unauthorized file upload attempts to personal cloud storage or unapproved SaaS tools stopped by DLP controls.
  • Web Filter Exception Review Rate: Tracks the percentage of temporary URL whitelists and domain category overrides reviewed and revalidated every three months in Jira.
  • Off-Network Web Gateway Coverage: Measures the percentage of remote and roaming laptops running active, fully updated cloud web filtering agents.
  • Web-Based Malware Infection Count: Tracks the number of successful drive-by downloads or malware incidents originating from web browsing activity.
  • Category Override Ticket Resolution Time: Measures the average time required by IT support to process and resolve legitimate business website unblock requests.
  • Uncategorized Domain Block Rate: Tracks the percentage of connection attempts to newly registered or uncategorized high-risk domains intercepted by security gateways.
  • SSL/TLS Decryption Coverage Rate: Measures the proportion of encrypted HTTPS web traffic successfully decrypted and scanned for malicious payloads.

Annex A 8.23 Web filtering links to several other ISO 27001 components:

  • Clause 8.1 (Operational Planning): Directs the execution of web filtering.
  • ISO 270001 Annex A 8.7 (Malware Protection): Web filtering acts as a primary preventative control.
  • ISO 27001 Annex A 5.10 (Acceptable Use): Defines the rules users must follow online.
ISO 27001 Web Filtering Explained – Annex A 8.23 - ISO 27001.com
ISO 27001 Web Filtering Explained – Annex A 8.23
ISO 27001 Annex A 8.23