Skip to content
arrow_back
search
ISM-0961 policy ASD Information Security Manual (ISM)

Restrict Active Content with Web Filters

Web filters block active content from unapproved websites.

record_voice_over

Plain language

Using web filters to restrict active content from unapproved websites is like having a security guard at the entrance of a building who only lets in trusted people. This is important because if you don't control what content can enter your organisation's computers, malicious software could slip in and cause massive problems, like slowing down important services or stealing sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Client-side active content is restricted by web content filters to an organisation-approved list of domain names.
policy ASD Information Security Manual (ISM) ISM-0961
priority_high

Why it matters

Without web filters, active content from malicious sites can exploit vulnerabilities, leading to data breaches and operational disruption.

settings

Operational notes

Maintain the organisation-approved domain allowlist, update it regularly, and review web filter logs/alerts for blocked active content to detect misuse.

Mapping detail

Mapping

Direction

Controls