Web Filtering Control (8.23)
Web Filtering is a security control that involves managing and restricting the external websites employees can reach, in order to reduce exposure to malicious or inappropriate content. In practice, organizations use technical tools to block or limit access to certain sites based on security and business policies. It was introduced as a new control in the ISO 27001:2022 revision.
Control 8.23 (Web Filtering) is a reference control listed in Annex A of ISO/IEC 27001:2022 and detailed in ISO/IEC 27002:2022. It calls for managing access to external websites using technical controls to reduce exposure to malicious content and to restrict access to sites that conflict with security and business policies, thereby mitigating risks such as malware infection and access to inappropriate resources. As one of the new controls introduced in the 2022 revision, it is a reference control rather than a mandatory requirement: like other Annex A controls, its applicability is determined through the organization's risk assessment and documented in the Statement of Applicability. Its implementation typically encompasses monitoring and blocking or restricting web access, though the specific technical measures depend on organizational scope, policies, and risk decisions.
Why it matters
Web browsing is one of the most common ways malicious content reaches an organization's endpoints. By managing and restricting access to external websites, Control 8.23 aims to reduce exposure to malware and to sites that conflict with an organization's security and business policies. Reducing the surface through which harmful or inappropriate content can enter the environment is a practical way to lower the likelihood of infection and misuse.
Control 8.23 was introduced as a new control in the ISO 27001:2022 revision, reflecting the increased emphasis on managing web-based risks in the updated standard. As a reference control listed in Annex A and detailed in ISO/IEC 27002:2022, its applicability is not automatic: organizations determine whether and how to apply it through their risk assessment, and they record that decision in the Statement of Applicability. This means the control matters most where an organization's risk profile identifies web access as a meaningful threat vector.
It is worth noting the boundaries of this control. Web filtering reduces exposure to malicious or inappropriate content but does not guarantee freedom from compromise, and the specific technical measures adopted depend on organizational scope, policies, and risk decisions. Like all Annex A controls, its presence in a certified ISMS reflects only what falls within the defined scope of that management system.
Who it's relevant to
Inside Web Filtering Control (8.23)
Common questions
Answers to the questions practitioners most commonly ask about Web Filtering Control (8.23).