4.4.1 Create a Web Filtering Profile

Information

Ensure FortiGuard Category-based Web filtering is blocking Security Risk categories

Websites categorized under \\"Security Risk\\" pose significant threats to an organization's network and users. Categories such as \\"Dynamic DNS\\", \\"Malicious Websites\\", \\"Phishing\\", and \\"Spam URLs\\" are often associated with cyber threats and serve as initial access vectors for attacks such as malware distribution, phishing schemes, command-and-control activities, and data theft.

If any websites or web pages that fall under the FortiGuard URL Database Categories \\"Dynamic DNS\\", \\"Newly Observed Domains\\", or \\"Newly Registered Domains\\" are required to be allowed, this based on an organization's policy, those specific entries should be configured under \\"Monitor\\" action in the web filter configuration.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Apply Web Filter profile to the firewall policy or SD-WAN and ensure that the Security Risk categories, including Malicious Websites, Phishing, and Spam URLs, are configured to Block.

Impact:

Setting the FortiGuard URL Database Categories \\"Newly Observed Domains\\" or \\"Newly Registered Domains\\" to \\"Block\\" action, can significantly impact user access to websites, particularly newly created website and/or uncategorized websites while it's relation to unrated category.

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4(11)

Plugin: FortiGate

Control ID: d0e5d466f2e67494dde4e9a4c865798723a1ea60984de92e752eea3aab7cf7fa