Skip to main content
Category: Technical Security Controls

Web Filtering Control (8.23)

Also known as: Annex A 8.23, Control 8.23, A.8.23 Web Filtering, ISO 27002 Control 8.23
Simply put

Web Filtering is a security control that involves managing and restricting the external websites employees can reach, in order to reduce exposure to malicious or inappropriate content. In practice, organizations use technical tools to block or limit access to certain sites based on security and business policies. It was introduced as a new control in the ISO 27001:2022 revision.

Formal definition

Control 8.23 (Web Filtering) is a reference control listed in Annex A of ISO/IEC 27001:2022 and detailed in ISO/IEC 27002:2022. It calls for managing access to external websites using technical controls to reduce exposure to malicious content and to restrict access to sites that conflict with security and business policies, thereby mitigating risks such as malware infection and access to inappropriate resources. As one of the new controls introduced in the 2022 revision, it is a reference control rather than a mandatory requirement: like other Annex A controls, its applicability is determined through the organization's risk assessment and documented in the Statement of Applicability. Its implementation typically encompasses monitoring and blocking or restricting web access, though the specific technical measures depend on organizational scope, policies, and risk decisions.

Why it matters

Web browsing is one of the most common ways malicious content reaches an organization's endpoints. By managing and restricting access to external websites, Control 8.23 aims to reduce exposure to malware and to sites that conflict with an organization's security and business policies. Reducing the surface through which harmful or inappropriate content can enter the environment is a practical way to lower the likelihood of infection and misuse.

Control 8.23 was introduced as a new control in the ISO 27001:2022 revision, reflecting the increased emphasis on managing web-based risks in the updated standard. As a reference control listed in Annex A and detailed in ISO/IEC 27002:2022, its applicability is not automatic: organizations determine whether and how to apply it through their risk assessment, and they record that decision in the Statement of Applicability. This means the control matters most where an organization's risk profile identifies web access as a meaningful threat vector.

It is worth noting the boundaries of this control. Web filtering reduces exposure to malicious or inappropriate content but does not guarantee freedom from compromise, and the specific technical measures adopted depend on organizational scope, policies, and risk decisions. Like all Annex A controls, its presence in a certified ISMS reflects only what falls within the defined scope of that management system.

Who it's relevant to

Security Engineers and IT Administrators
Those responsible for configuring and maintaining web filtering tools implement the technical measures that block or restrict access to external websites. Their choices about what to filter and monitor translate the control's intent into operational reality, and should align with the organization's security and business policies.
GRC and Compliance Managers
Because 8.23 is a reference control whose applicability is determined through risk assessment, GRC professionals decide whether to apply it and document that decision in the Statement of Applicability. They ensure the rationale for including or excluding the control is defensible and consistent with the organization's risk decisions.
ISO 27001 Auditors and Certification Bodies
Auditors assessing an ISMS against ISO/IEC 27001:2022 review how the organization has treated Control 8.23, including whether it appears in the Statement of Applicability and how any implemented measures reflect the risk assessment. Their assessment covers only the defined scope of the ISMS.
Organizations Transitioning to the 2022 Revision
Because 8.23 was introduced as a new control in the 2022 revision, organizations moving from the 2013 edition need to evaluate this control specifically, determine its applicability against their risk profile, and update their Statement of Applicability accordingly.

Inside Web Filtering Control (8.23)

Annex A Reference Control (2022 revision)
Web Filtering (8.23) is one of the reference controls listed in Annex A of the ISO/IEC 27001:2022 edition, which restructured Annex A into 93 controls across four themes. It appears under the Technological controls theme. As with all Annex A controls, its inclusion in an organisation's ISMS is determined through risk assessment and documented in the Statement of Applicability rather than being automatically mandatory.
Purpose
The control addresses managing access to external websites to reduce exposure to malicious content and to help prevent systems from being compromised through web-based threats. The specific implementation depends on the organisation's risk profile and scope.
Scope Determination via Statement of Applicability
Whether and how Web Filtering is applied is informed by the organisation's risk assessment and recorded in the Statement of Applicability. An organisation may justify inclusion or exclusion based on its assessed risks, so the control is not universally implemented in the same way across ISMS scopes.
Relationship to Guidance in ISO 27002
While ISO/IEC 27001 Annex A lists the control as a reference, more detailed implementation guidance for controls such as Web Filtering is typically found in ISO/IEC 27002, which serves as the accompanying guidance standard rather than a certifiable requirement.

Common questions

Answers to the questions practitioners most commonly ask about Web Filtering Control (8.23).

Is web filtering a mandatory control that every ISO 27001 certified organization must implement?
Not necessarily. Annex A controls, including web filtering (numbered 8.23 in the ISO/IEC 27001:2022 revision), are reference controls that an organization selects through its Statement of Applicability, informed by its risk assessment. The certifiable requirements are in clauses 4 through 10. An organization may justify excluding or tailoring an Annex A control if it is not applicable to the defined scope of its ISMS, though such decisions are typically documented and reviewed by the certification body.
Does implementing web filtering for ISO 27001 mean the same control satisfies my SOC 2 requirements?
Not automatically. Mapping between ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria is possible but partial, and satisfying one framework does not automatically satisfy the other. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, while ISO 27001 is a certification issued by an accredited certification body. A web filtering measure might contribute evidence relevant to both, but each framework evaluates controls against its own criteria and scope, and the auditor or certification body makes an independent assessment.
How is web filtering typically documented within the Statement of Applicability?
In most engagements, the Statement of Applicability records whether the control is applicable, the justification for its inclusion or exclusion, and a reference to how it is implemented. For web filtering, organizations typically note the risks it addresses, the systems and user populations in scope, and the associated policies or technical configurations, so that a certification body can trace the decision back to the risk assessment.
What kinds of evidence might an auditor or certification body request for a web filtering control?
Depending on scope, auditors typically look for documentation and operational evidence that the control is designed and, where operating effectiveness is assessed, functioning over time. This can include filtering policies, configuration settings, category or blocklist definitions, and logs or reports showing the control in operation. The specific evidence depends on the assessor, the review period, and how the control was defined in the applicable documentation.
How does web filtering relate to other controls in the ISMS rather than standing alone?
Web filtering is generally implemented as one layer among several related measures. It typically works alongside controls addressing malware protection, network security, and acceptable use, and its scope and configuration are usually informed by the same risk assessment that drives other Annex A selections. Organizations often reference guidance in ISO 27002 for additional implementation detail, as ISO 27002 provides supporting guidance for the reference controls listed in ISO 27001 Annex A.
What are the boundaries of what a web filtering control can be relied upon to achieve?
A web filtering control addresses only the risks within its defined scope, such as access to specified categories of external web content, and does not guarantee freedom from all web-based threats or breaches. Its coverage depends on how it is configured, the systems and users it applies to, and how it interacts with other controls. Where the control is evaluated within a SOC 2 report, the report attests only to the controls and period covered; where it is included in an ISO 27001 certificate, that certificate covers only the defined scope of the ISMS.

Common misconceptions

Web Filtering (8.23) is a mandatory control that every ISO 27001-certified organisation must implement.
Annex A controls are reference controls selected through risk assessment and documented in the Statement of Applicability. The certifiable requirements are in clauses 4 through 10. An organisation may justifiably exclude a given Annex A control depending on its scope and assessed risks, so implementation is not automatically required.
Implementing Web Filtering to satisfy ISO 27001 also satisfies the equivalent requirement in a SOC 2 examination.
SOC 2 and ISO 27001 are distinct frameworks with only partial mapping between them. SOC 2 is an attestation examination performed by a licensed CPA firm against the Trust Services Criteria, whereas ISO 27001 is a certification against a management system standard. Satisfying a control in one framework does not automatically satisfy the other, and the Trust Services Criteria are not the same as Annex A controls.
Control 8.23 exists in the same form and control number across all editions of ISO 27001.
The 8.23 Web Filtering designation reflects the 2022 revision, which restructured Annex A into 93 controls across four themes. The prior 2013 version had a different structure and 114 controls. Control numbers and counts depend on the edition, so the version should always be specified when citing them.

Best practices

Base the decision to include or exclude Web Filtering on a documented risk assessment, and record the justification in the Statement of Applicability rather than assuming the control is mandatory.
Specify the ISO/IEC 27001:2022 edition when referencing control 8.23, since control numbering and counts differ across editions.
Consult ISO/IEC 27002 for more detailed implementation guidance, treating it as guidance that supports, but is separate from, the certifiable clause 4 through 10 requirements.
Align web filtering implementation with the organisation's assessed web-based threat risks, tailoring the approach to scope rather than applying a one-size-fits-all configuration.
Where the organisation also undergoes a SOC 2 examination, map controls carefully and treat any correspondence with the Trust Services Criteria as partial, confirming coverage separately for each framework.
Document the boundaries of what the control covers within the defined ISMS scope, recognising that certification applies only to that defined scope.