View Categories

A8.23 Web filtering

4 min read

Web filtering involves controlling access to internet content by restricting access to certain websites or categories deemed unsafe, unproductive, or non-compliant with organizational policies. Effective web filtering helps protect against malware, phishing, and data leakage while maintaining productivity and compliance.

ISO 27001 A8.23 Web filtering mandates the implementation of controls to manage user access to web resources, reducing the risk of security incidents and ensuring that internet usage aligns with business and regulatory requirements.

Implementation Guide #

Step 1: Define Web Access Policies

  • Establish acceptable use policies outlining which types of websites are allowed or blocked (e.g., social media, gambling, streaming, file-sharing).
  • Identify business units or user roles that require different levels of internet access.
    → Tool Recommendation: Use Confluence, SharePoint, or Notion for policy documentation and distribution.

Step 2: Deploy Web Filtering Solutions

  • Implement DNS-based or proxy-based web filtering solutions to manage and enforce access.
  • Filter web traffic by category, URL, or keyword to prevent access to harmful or inappropriate content.
    → Tool Recommendation:
  • Cisco Umbrella (DNS-based filtering)
  • Zscaler Internet Access (cloud proxy)
  • FortiGuard Web Filtering
  • Barracuda Web Security Gateway
  • Microsoft Defender for Endpoint (with web control)

Step 3: Apply Filtering Based on User Roles and Risk Profiles

  • Use directory integration (e.g., Active Directory) to apply filtering policies per user, group, or device.
  • Provide different levels of access for employees, contractors, and guests.

Step 4: Enable SSL Inspection for HTTPS Traffic (Optional but Recommended)

  • Enable SSL decryption and inspection to monitor and filter encrypted traffic.
  • Ensure compliance with privacy regulations and inform users about monitoring.
    → Tool Recommendation: Palo Alto NGFW, Sophos XG, Blue Coat ProxySG

Step 5: Monitor and Log Web Activity

  • Monitor web traffic logs to detect suspicious behavior, policy violations, or attempts to access blocked sites.
  • Generate reports for auditing and compliance purposes.
    → Tool Recommendation: Splunk, Elastic Stack, Wazuh, or FortiAnalyzer

Step 6: Regularly Review and Update Web Filters

  • Adjust filters based on evolving threats, productivity needs, or changes in business operations.
  • Review incident reports and user feedback to refine filtering categories and exceptions.

Templates #

  • Web Access Control Policy
  • Web Filtering Configuration Checklist
  • User Role-Based Filtering Matrix
  • Web Activity Log Review Report
  • Exception Request Form

Example #

A legal firm experienced phishing attempts via compromised websites. They implemented Cisco Umbrella and FortiGate with category-based filtering, blocking high-risk sites like webmail, peer-to-peer, and new domains. They applied different policies for IT staff (broader access) and admin staff (restricted access). Logging and alerts via Splunk helped detect violations and track compliance.

How to Comply #

To comply with ISO 27001 A.8.23, organizations should:

  • Define and enforce acceptable internet usage policies.
  • Implement web filtering tools to restrict harmful or non-business-related websites.
  • Monitor and log user web activity.
  • Provide access based on business need and user roles.
  • Regularly update and review filtering rules and policies.

How to Pass an Audit #

Key Documents to Prepare:

  • Web Filtering Policy
  • Filtering Tool Configuration Reports
  • User Access Role Definitions
  • Web Activity and Exception Logs
  • Audit Reports or Incident Logs

What the Auditor Will Check:

  • Are web filtering controls in place and documented?
  • Is internet access aligned with user roles and responsibilities?
  • Are activities monitored, logged, and reviewed regularly?
  • Are filtering policies reviewed and updated periodically?

Top 3 Mistakes People Make #

  • Overblocking access, causing disruption to legitimate business tasks.
  • Failing to log or monitor web traffic, missing early signs of compromise.
  • Not tailoring filtering policies based on user roles or risk profiles.

ISO 27001 Web Filtering FAQ #

Q1: Is it necessary to block social media and streaming sites?
Not always. It depends on your organization’s policy and risk profile. Some roles may require access, while others don’t.

Q2: Can web filtering be bypassed using VPNs or proxies?
Yes—if not configured properly. Use firewalls and deep packet inspection to block unauthorized VPN/proxy use.

Q3: Is DNS filtering enough?
DNS filtering is a strong first line of defense, but proxy or firewall-based filtering provides deeper inspection and control.

ISO 27001 Controls and Attribute Values #

Control

Attribute Value

A.8.23 Web Filtering

Preventive, Technical, Operational

Purpose

To reduce exposure to malicious content and ensure responsible web usage.

Applicability

All employees and systems with internet access.

ISO 27001 Domains

Communications Security, Operations Security

 

A strong web filtering strategy prevents harmful content from entering the network, improves productivity, and supports compliance with both internal and regulatory requirements.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now