Cyber Resilience

← ISO 27001 Annex A

A.8.23 Technological

Web filtering

AttributesPreventiveC·I·AProtectSystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (13)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (17)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (5)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Related weaknesses / CWE (14)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (396)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←M →PT1006←PT1008→PT1011←PT1014←MT1016.001←MT1020←MT1027.001←MT1027.002←MT1027.003←MT1027.005←MT1027.006←M →PT1027.007←MT1027.008←PT1027.009←PT1027.010←MT1027.011←PT1027.012←MT1027.014←MT1027.017←M →PT1027.018←MT1030←PT1036←MT1036.002←MT1036.003←MT1036.005←MT1036.007←MT1036.008←MT1036.009←MT1036.012←MT1041←M →PT1048←M →PT1048.001←MT1048.002←MT1048.003←M →PT1055←MT1055.001←MT1055.002←MT1055.003←MT1055.004←MT1055.005←MT1055.008←PT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1056←M →PT1059←M →PT1059.001←MT1059.007←M →PT1070←MT1070.010←PT1071←M →PT1071.001←M →PT1071.002←MT1071.003←MT1071.004←M →PT1071.005←MT1078←PT1078.004←MT1090←MT1090.001←M →PT1090.002←M →PT1090.003←M →PT1090.004←MT1095←MT1098.005←PT1102→PT1102.001←M →PT1102.002→PT1102.003→PT1104←M →PT1105←M →PT1110.001→PT1127←MT1127.001←MT1127.002←M →PT1132←MT1132.001←MT1132.002←MT1133←MT1176←M →PT1176.001←M →PT1185←MT1187←PT1189←M →PT1190←M →PT1197←P →PT1203←M →PT1204←M →PT1204.001←M →PT1204.002←M →PT1204.003←PT1204.004←M →PT1204.005←PT1205←MT1205.001←PT1205.002←MT1207←PT1211←PT1216←MT1216.001←MT1218←MT1218.001←PT1218.004←MT1218.005←M →PT1218.007←MT1218.008←PT1218.010←M →PT1218.011←PT1218.012←PT1218.013←PT1219←M →PT1219.001←MT1219.002←M →PT1219.003←MT1220←PT1221←M →PT1480←PT1480.001←PT1484←PT1484.002←PT1496.002→PT1497←PT1498←PT1505.003←MT1528←MT1534←M →PT1535←MT1537←MT1539←M →PT1542←MT1542.002←PT1542.003←MT1546.012←PT1546.015←MT1548←PT1550←MT1550.001←MT1550.004←FT1553←MT1553.001←PT1553.002←PT1553.003←PT1553.004←MT1553.005←MT1557←M →PT1557.003←MT1557.004←MT1566→PT1566.001→PT1566.002←M →PT1566.003←M →PT1566.004←PT1567→PT1567.001←M →PT1567.002←M →PT1567.003→PT1567.004←M →PT1568→PT1568.001→PT1568.002←M →PT1568.003←M →PT1571←MT1572←M →PT1573←MT1573.001←MT1573.002←MT1574←MT1574.001←MT1574.013←PT1578.001←PT1578.002←PT1578.004←PT1583←MT1583.001←M →PT1583.002←M →PT1583.003←MT1583.004←M →PT1583.005←MT1583.006←MT1583.007←MT1583.008←P →PT1584←MT1584.001←MT1584.002←MT1584.003←MT1584.004←M →PT1584.006←MT1584.007←MT1584.008←MT1585.002←MT1586.002←MT1587.001←MT1588←MT1588.001←M →PT1588.002←MT1588.004←PT1589→PT1589.001→PT1595.003→PT1598←M →PT1598.001←M →PT1598.002←MT1598.003←M →PT1599←MT1599.001←MT1601.002←PT1606←MT1606.001←MT1608←M →PT1608.001←MT1608.002←PT1608.003←PT1608.004←M →PT1608.005←M →PT1608.006←MT1610←PT1612←MT1620←PT1621←PT1659←M →PT1665←MT1674←PT1678←PT1684←M →PT1684.001←P →PT1684.002←PT1685←MT1685.003←MT1686←MT1686.001←MT1686.002←MT1686.003←MT1687←PT1688←MT1689←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (6)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.