A.8.23 A.8 · Technological Controls New in 2022

A.8.23 — Web filtering

Manage access to external websites to reduce exposure to malicious content.

Also written as A8.23, Annex A 8.23, ISO 27001:2022 A.8.23, ISO27001 A.8.23.

What ISO 27001 A.8.23 requires

Web filtering is one of 34 Technological Controls in ISO/IEC 27001:2022 Annex A. Manage access to external websites to reduce exposure to malicious content. Technological controls are tested against system state, not policy text: expect the auditor to ask for configuration exports, tickets, or console screenshots showing the control is enforced in the live environment.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.8.23, gather artefacts such as:

  • Web filtering policy with approved and blocked category list
  • Web proxy or content filter configuration
  • Web filtering logs and blocked request records
  • Exception and bypass approval records

How to implement A.8.23

  1. Filter by category with a documented rationaleA block list of categories is the norm, but the control is assessed on whether the choices are deliberate. Record why each category is blocked — malware risk, legal exposure, productivity is generally not a security justification — so the configuration traces to a decision.
  2. Cover remote and mobile usersFiltering that only applies on the corporate network stopped being adequate when the workforce left the office. If your filtering is proxy-based and off-network devices bypass it, that gap is the finding.
  3. Handle exceptions formallySecurity researchers, marketing teams and developers all have legitimate reasons to reach blocked categories. Build an approval path with an owner and an expiry, rather than the informal permanent bypass that these requests usually become.
  4. Keep the logs and actually use themBlocked-request logs are evidence the control operates, and they are also a detection source — repeated blocks to malware categories from one device is an incident signal, not just a statistic.
  5. Connect it to awarenessUsers who understand why a page is blocked raise fewer bypass requests. Linking the block page to guidance is a small change that reduces the exception volume this control otherwise generates.

Common audit findings for A.8.23

What actually gets raised against A.8.23, in rough order of how often it comes up:

Scoping A.8.23

A.8.23 is new in ISO 27001:2022. It is one of the more genuinely excludable new controls — an organisation whose personnel have no general web access from managed devices can justify exclusion — but that exclusion needs to be argued from the risk assessment, not asserted. Where a modern secure web gateway or SASE service already exists, the control is usually satisfied by documenting what is already configured.

How A.8.23 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.8.23 aligns with:

SOC 2: CC6.6 Protection against external threats, CC6.8 Prevention and detection of malicious software

NIST CSF 2.0: PR.PS-05 Unauthorized software prevention, PR.IR-01 Network protection from unauthorized access

ISO 27001:2013 mapping

A.8.23 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.

Map A.8.23 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.8.23 in the Risk Register.

Related Annex A controls

A.6.7 Remote working A.8.20 Networks security A.8.21 Security of network services A.8.22 Segregation of networks A.8.27 Secure system architecture and engineering principles A.8.31 Separation of development, test and production environments

See all 34 Technological Controls →

Frequently asked questions

Is ISO 27001 A.8.23 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.8.23 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.8.23?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.8.23 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.8.23 map to in SOC 2 and NIST CSF?

A.8.23 aligns with SOC 2 CC6.6, CC6.8 and NIST CSF PR.PS-05, PR.IR-01. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

Is A.8.23 a new control in ISO 27001:2022?

Yes. A.8.23 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.

What are the most common audit findings for A.8.23?

Filtering enforced on-network only, with remote devices entirely unfiltered. Permanent bypasses granted informally with no expiry or review.