Skip to content
arrow_back
search
Annex A 8.23 verified ISO/IEC 27001:2022

Web Filtering to Reduce Malicious Website Exposure

Limit access to risky websites to avoid malware and phishing threats.

record_voice_over

Plain language

This control is about making sure your team members aren't accidentally stumbling onto harmful websites that could infect your systems with viruses or steal your information. Think of it like having a bouncer at a club, but for your internet browsing: keeping the bad stuff out and only letting in the good.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Access to external websites shall be managed to reduce exposure to malicious content.
verified ISO/IEC 27001:2022 Annex A 8.23
priority_high

Why it matters

Unfiltered access to websites can lead to malware infections and phishing attacks, compromising sensitive data and disrupting operations.

settings

Operational notes

Regularly update web filtering categories, validate block/allow lists, and review proxy/DNS logs to tune rules for new malicious sites.

Mapping detail

Mapping

Direction

Controls