Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Solution Architect

previous version on gdrive

A.8.23 Web Filtering

Control Objective

Access to external websites shall be managed to reduce exposure to malicious content.

Policy Statement

anDREa manages and restricts outbound web traffic based on the environment's specific risk profile. In highly sensitive data analysis spaces (myDRE Workspaces), strict allowlisting boundaries prevent unauthorized data exfiltration and malware exposure. In corporate environments, security relies on managed, secure endpoint architectures paired with mandatory user accountability and threat awareness.


Web Access Controls by Environment

To balance rigorous information security with operational agility, web filtering policies are bifurcated across two primary operational domains:

1. Development & Production Environments (myDRE Workspaces)

Research environments operate under a default-deny paradigm to safeguard hosted data:

  • Proxy-Based Routing: By default, outbound internet connectivity is disabled within myDRE Workspaces. When internet access is requested, it is channeled through a dedicated forward-proxy server.
  • Domain and IP Allowlisting: Outbound web access is restricted strictly to pre-approved destinations via explicit Domain and IP Allowlisting managed via the customer portal.
  • Risk Aknowledgement: Workspace users must explicitly sign off on a risk confirmation protocol before additional external domains or IP pools are whitelisted for their research environment.
  • Malicious Content Detection: All traffic streams and workspace endpoints are continuously scrutinized for malicious payloads or connection behaviors by Microsoft Defender for Cloud (see A.08.07 - Protection against malware and A.08.16 - Monitoring activities).

2. Corporate Operations (Office Employees)

Because business, administrative, and operations teams require unrestricted web navigation to execute daily tasks, open browser sessions are permitted with alternative device-level hardening:

  • Unmanaged Browser Routing: Centralized web content filtering or uniform web blocks are not applied to office personnel browser sessions.
  • Hardware Isolation (ChromeOS): To mitigate the risk of drive-by downloads or browser exploits, office employees are provisioned with corporate-managed Chromebooks. These endpoints leverage hardware sandboxing and read-only system partitions to limit malware execution (see A.08.01 - User end point devices).
  • Workforce Compliance: Personnel must review, sign, and adhere to A.06.07 - Remote working upon onboarding and annually thereafter. This training reinforces safe browsing habits, phishing recognition, and methods to minimize exposure to malicious external content.