A.8.23Web filtering
Manage access to external websites to reduce exposure to malicious content and to keep harmful or inappropriate sites out of your environment.
A.8.23 is covered by 1 Sekit CSF control. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
In practice
Web filtering usually comes down to one setting that either happens or does not: whether every company device points at a filtering DNS resolver, or whether some devices, especially personal phones and contractor laptops, still resolve through the ISP's default DNS with no protection at all. The gap shows up during an incident review, when the malicious domain a phishing email pointed to turns out to have been reachable from half the fleet. A working setup routes all managed devices through a resolver that blocks known-malicious domains, locks the company's own public DNS records with registrar transfer protections, and checks periodically that no device has quietly reverted to an unfiltered network configuration.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.