A.8.23 Technological
Web filtering
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-4mostlyaligns with — Both enforce policy-based restrictions on the flow of information between users and external web destinations.
- SC-7mostlyaligns with — Both controls use boundary-level filtering to block access to known malicious or unauthorized external resources.
- AT-2partialaligns with — Both require user awareness training on the risks of accessing unsafe or unauthorized web content.
- CM-7partialaligns with — Both limit the functionality available to users by restricting access to specific categories of web resources.
- SI-4partialaligns with — Both rely on threat intelligence feeds to identify and block malicious web sites and command-and-control infrastructure.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.IR-01mostlyaligns with — Web filtering implements a technical control that blocks unauthorized or malicious network destinations, directly supporting the outcome of protecting networks and environments from unauthorized logical access and usage.
- GV.PO-01partialaligns with — Establishing rules for appropriate web use and keeping them current supports the creation of cybersecurity risk management policy based on organizational context and priorities.
- ID.RA-02partialaligns with — The control incorporates threat intelligence to identify and block malicious websites, aligning with the outcome of receiving cyber threat intelligence from external sources.
- PR.AT-01partialaligns with — The control requires training personnel on safe web usage and organizational rules, which contributes to ensuring personnel have the knowledge to perform tasks securely.
- PR.PS-05partialaligns with — By preventing access to malicious or unauthorized web resources, the control reduces the risk of unauthorized software being downloaded or executed on organizational systems.
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (24)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — By blocking known malicious or phishing domains, the control reduces the chance that users will reach attacker-controlled pages that could exfiltrate sensitive data or credentials.
- CWE-352partialmitigates — By denying access to phishing or malicious sites, the control lowers the likelihood that a user will be tricked into submitting a forged request that performs an unintended action on another site.
- CWE-451partialmitigates — Web filtering can block known phishing sites that exploit UI misrepresentation.
- CWE-508partialprevents — Web filtering can block delivery vectors for non-replicating malware.
- CWE-509partialprevents — Web filtering blocks malware downloads that lead to virus/worm replication.
- CWE-601partialmitigates — Preventing access to attacker-controlled or malicious sites stops users from being redirected to untrusted locations via open-redirect or phishing links.
- CWE-1021nonenone — Web filtering can block or sandbox untrusted frames, but does not enforce application-level frame-busting or CSP.
- CWE-1022nonenone — Web filtering can block or warn on links to untrusted external domains, reducing the attack surface for window.opener abuse.
- CWE-346nonenone — Web filtering can block untrusted sources but is not a general origin-validation mechanism.
- CWE-525nonenone — Web filtering can block risky sites but does not directly govern browser caching of sensitive data.
- CWE-646nonenone — Web filtering can block risky file extensions but does not address server-side file handling logic.
- CWE-80nonenone — Web filtering can block some reflected XSS payloads at the network edge.
- CWE-829nonenone — Blocking domains that serve malware or untrusted scripts prevents the browser from automatically including functionality from an attacker-controlled source.
- CWE-830nonenone — Web filtering can prevent loading of untrusted web functionality, directly mitigating the weakness.
- CWE-85nonenone — Web filtering can block some XSS payloads but does not address doubled-character encoding at the application layer.
- CWE-942nonenone — Web filtering can block untrusted domains at the network level, partially mitigating permissive cross-domain policies.
Mitigated MITRE ATT&CK techniques (6)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1189mostlyprevents — Preventing access to malicious websites reduces the chance that drive-by downloads or browser exploits will succeed.
- T1204.001mostlyprevents — Filtering malicious links before users can click them lowers the probability that a user will execute malware delivered through a malicious URL.
- T1566.002mostlyprevents — Blocking known phishing domains and malicious sites directly prevents users from reaching attacker-controlled links that deliver initial payloads.
- T1071.001partialprevents — By denying access to attacker-registered or compromised domains, the control reduces the viability of web protocols as covert C2 channels.
- T1102nonemitigates — Filtering out known malicious web services and C2 domains limits the adversary’s ability to establish or maintain web-based command-and-control channels.
- T1567.002nonemitigates — Blocking access to cloud storage and file-sharing sites that are not business-approved limits opportunities for large-scale data exfiltration over web services.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.