Skip to content
arrow_back
search
Annex A 8.23 verified ISO/IEC 27001:2022

Web Filtering to Reduce Malicious Website Exposure

Limit access to risky websites to avoid malware and phishing threats.

record_voice_over

Plain language

This control is about making sure your team members aren't accidentally stumbling onto harmful websites that could infect your systems with viruses or steal your information. Think of it like having a bouncer at a club, but for your internet browsing: keeping the bad stuff out and only letting in the good.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Access to external websites shall be managed to reduce exposure to malicious content.
verified ISO/IEC 27001:2022 Annex A 8.23
priority_high

Why it matters

Unfiltered access to websites can lead to malware infections and phishing attacks, compromising sensitive data and disrupting operations.

settings

Operational notes

Regularly update web filtering categories, validate block/allow lists, and review proxy/DNS logs to tune rules for new malicious sites.

build

Implementation tips

  • The IT manager should identify risky website categories, like those known for phishing or distributing malware. They can do this by referencing lists from cybersecurity agencies such as the ASD. Once identified, these websites should be blocked using web filtering tools available in many security software packages.
  • The HR department should ensure that all employees receive training on recognising unsafe websites and understanding why certain sites are blocked. This can be done through regular workshops or training sessions, where employees learn about internet safety and the organisation's policies.
  • The board should approve a clear policy on web usage that outlines which types of websites are banned and why. This policy should be informed by both ISO 27002:2022 guidance and the requirements under Australian regulations like the Privacy Act 1988.
  • IT staff should regularly update the web filtering system to adapt to new threats and business needs. This involves staying informed with threat intelligence reports (such as those provided by ASD) and adjusting block lists accordingly.
  • The security team should conduct regular audits of the web filtering system to ensure it is functioning as intended. This involves testing whether known malicious sites are effectively blocked and confirming that legitimate business needs are not hindered.
fact_check

Audit / evidence tips

  • AskThe latest web usage policy document
  • AskA demonstration of the web filtering system in action
  • AskTraining records or materials regarding web safety training
  • AskUpdates or change logs of web filter configurations
  • AskReports or alerts generated from the web filtering system
link

Cross-framework mappings

How Annex A 8.23 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

Control Notes Details
link Related (1) expand_less
E8-AH-ML1.2 E8-AH-ML1.2 requires that web browsers do not process Java content from the internet to reduce exposure to exploitation via browser-borne...

ASD ISM

Control Notes Details
layers Partially meets (2) expand_less
ISM-1236 ISM-1236 requires web content filters to block malicious domains, dynamic domains, and domains that can be registered anonymously for free
ISM-1485 ISM-1485 requires blocking browsers from processing web advertisements from the internet to reduce exposure to malicious content delivere...
sync_alt Partially overlaps (4) expand_less
ISM-0659 ISM-0659 requires that files imported or exported via gateways or cross domain solutions (CDSs) undergo content filtering checks to detec...
ISM-0958 ISM-0958 requires an organisation-approved allow/block list of domain names or website categories for all HTTP/HTTPS traffic through gate...
ISM-1237 ISM-1237 requires web content filtering to be applied to outbound web traffic where appropriate
ISM-2068 ISM-2068 requires organisations to strictly limit internet connectivity to only those networked devices that require access
handshake Supports (3) expand_less
ISM-0258 Annex A 8.23 requires organisations to manage access to external websites to reduce exposure to malicious content
ISM-0260 Annex A 8.23 requires organisations to manage access to external websites to reduce exposure to malicious content
ISM-0874 ISM-0874 requires all user devices to route internet access through the organisation’s gateway instead of direct connections
link Related (5) expand_less
ISM-0267 Annex A 8.23 requires managing access to external websites to reduce exposure to malicious content
ISM-0961 Annex A 8.23 requires external website access to be managed to reduce exposure to malicious content
ISM-0963 Annex A 8.23 requires organisations to manage access to external websites to reduce exposure to malicious content
ISM-1171 Annex A 8.23 requires organisations to manage access to external websites to reduce exposure to malicious content
ISM-1782 Annex A 8.23 requires external website access to be managed to reduce exposure to malicious content

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

school

Want to implement this control?

Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.

Mapping detail

Mapping

Direction

Controls