ISO27001:2022 – A8.23

Web Filtering

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.23

This new ISO27001 control has been introduced to ensure you protect systems from being compromised by malware and to prevent access to unauthorised web resources. The web presents significant risks to your organisation and has often been said that ‘WWW’ doesn’t stand for ‘World Wide Web’, but in fact is the ‘Wild Wild West’! 

This is because the Web is often seen as a lawless, borderless world which is uncontrollable.  That is a debate for another time, but it is true to say that it is almost impossible to control everything on the Web, but we can, and should take steps to filter what people can see. 

But what do we mean by ‘web filtering’? 

Web filtering refers to the process of controlling and managing access to websites or online content based on predetermined rules.

What does ISO 27001 – A8.23 require?

The standard states that “Access to external websites shall be managed to reduce exposure to malicious content.” (A8.23 – Web filtering)

 

Why is this required?

Web filtering plays an important role in protecting your business, your people and your reputation from malicious content and reputational damaged. It could also keep you out of court!

 Imagine that you didn’t filter what people could access on the internet, and simply allowed your teams to access anything they wanted at any time. Although you trust your teams, would you be comfortable with their accessing social media sites like TikTok, or Instagram whenever they wanted? How about shopping sites or gambling sites?

You might see no problem in this.

But what about pornography sites? What about sites offering free downloads of ‘cracked’ software? (Meaning no licence is required to use the software). 

We worked with a Call Centre for a major high street brand that had over 250 telephone operatives. After several complaints had been made, it was discovered that several people were accessing adult material and sharing links to images and videos..

Web filtering had not been established.

A number of employees felt extremely uncomfortable with the images being shared and the tone of conversations taking place.. Ultimately, this led to several people being dismissed for misconduct.

Could this have been prevented by establishing web filtering tools? Probably.

 Allowing free, unfiltered access to the internet also presents a risk to productivity within your organisation. As we all know, time seems to evaporate when we start using social media sites!

 

Putting this aside for a moment, it’s important to recognise that phishing emails often include links to external sites which would be flagged as suspicious by web filtering tools. This is an additional control to help in the fight against malware infection, as these sites aren’t just there to harvest data. They often contain malware intended to infect your networks and systems.

 

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include; 

What do you need to do?

Speak to your IT team to establish what forms of web filtering are in place. Speak to your IT team to find out what approach they have used for web filtering, as it can be implemented at different levels, including device, browser, or network level. Typical approaches include; 

  • Proxy-Based Filtering – Filtered using proxy services which restrict access to sites.
  • URL Filtering – Using established lists of banned URLs.
  • Keyword Filtering – Restricting access based on specific keywords.
  • DNS-Based Filtering – Limiting access to specific websites based on their Doman name.
  • Content Filtering – Scanning of websites for content which might be deemed unacceptable.

 Establish how rules have been defined, and identify any risks associated to this process. Who decided what is and is not permissible?  This also includes when sites can be accessed. 

 For example, you might determine that shopping sites are ok (e.g. Amazon.co.uk), but not between the hours of 9am and 12pm, and 2pm to 5pm.  This means that when people can still access these sites, but only during breaks, or after work.

The parameters you define are personal to your organisation, because different organisations will have different requirements.

For example, we worked with a law enforcement agency that investigated drugs. Terms used to describe drugs often change, and understanding what is available requires an understanding of what the drugs are, and what they do.  Therefore, the web filtering tools needed to allow searches to, and for all classes of drugs.  If web filtering tools had been too restrictive, then they couldn’t do their job.  Access to the sites they were using would be blocked in most organizations, but they allowed it based on need and risk.

Ensure you have an acceptable use policy in place which outlines what you deem to be acceptable use of the internet. For example you might outline that shopping is acceptable, but only between certain hours (as described above). Once this is in place you need to ensure personnel and other interested parties are aware of what your policy is. Include this within your training and awareness process, so that people understand why you have taken the actions you have taken.

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. Initially, this is a very IT focused control, and requires significant input from your IT function, so that you understand what web filtering tools are available to you. But you will need to agree web filtering rules with the business, as functions may have different access requirements.

Q&A

Do I need a policy?

No, you don’t need a topic-specific policy for web filtering, but you should outline what web filtering is in place and what you expect in your Acceptable Use Policy.

What if there is no web filtering in place?

Don’t leave this to chance. Web filtering is extremely important for all the reasons already stated above. You are protecting your people and your business from malicious content being accessed, and you are ensuring your people are being as productive as possible.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.23 –  Web Filtering