The organization is to manage which external websites can be reached, so that exposure to malicious content falls. Purpose: keep malware from compromising systems and stop people reaching web resources they are not authorized to use. Guidance: reduce the risk of personnel visiting sites with illegal content or known to host viruses or phishing, for example by blocking the IP addresses or domains concerned, which some browsers and anti-malware tools do automatically or can be set to do. Identify which kinds of website personnel should and should not reach, and consider blocking sites with upload functions unless there is a valid business reason, known or suspected malicious sites distributing malware or phishing, command and control servers, malicious sites identified through threat intelligence (5.7), and sites sharing illegal content. Before deploying filtering, set rules on using online resources safely and properly, including restrictions on undesirable or inappropriate sites and web applications, and keep them current. Train personnel to use online resources safely and properly, covering the rules, the contact point for security concerns and the exception process for reaching restricted resources for legitimate business reasons, and on not overriding browser warnings that a site is insecure. Other information: web filtering can use signatures, heuristics, lists of sites or domains that are allowed or prohibited, and bespoke configuration, to keep malicious software and activity off the network and systems.
This control maps to 55 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.