{"id":1214,"date":"2026-09-13T19:32:30","date_gmt":"2026-09-13T19:32:30","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1214"},"modified":"2026-09-13T19:32:30","modified_gmt":"2026-09-13T19:32:30","slug":"content-filtering","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/content-filtering\/","title":{"rendered":"Content Filtering"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CONTENT FILTERING\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Content filtering is a policy, not a product. The same rule can be enforced in four different places, and choosing the wrong one is why most deployments get switched off.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Network<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Content filtering is the practice of restricting what people can reach from company devices and networks. It covers everything from blocking known malicious sites to enforcing an acceptable-use policy, and it can be applied at the name lookup, in the web request, on the endpoint or in email. The technology is a detail. The policy decision comes first.<\/p>\n<\/div>\n\n<p>Two very different objectives hide inside content filtering, and confusing them is the most common reason a rollout fails.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#layers\">The four content filtering layers<\/a><\/li>\n    <li><a href=\"#jobs\">Two jobs that get confused<\/a><\/li>\n    <li><a href=\"#choose\">Choosing where to enforce<\/a><\/li>\n    <li><a href=\"#fails\">Where content filtering fails<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"layers\">The four content filtering layers<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 188\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"One content filtering policy enforced at four layers: DNS, web request, endpoint agent and email.\">\n  <defs><marker id=\"cf\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"52\" width=\"164\" height=\"72\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"96\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#1c267a\">One policy<\/text>\n  <text x=\"96\" y=\"103\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">What may be reached<\/text>\n  <line x1=\"182\" y1=\"88\" x2=\"204\" y2=\"88\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#cf)\"\/>\n\n  <rect x=\"212\" y=\"14\" width=\"176\" height=\"66\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"300\" y=\"40\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6f96\">Name lookup<\/text>\n  <text x=\"300\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Cheapest, domain only<\/text>\n\n  <rect x=\"212\" y=\"96\" width=\"176\" height=\"66\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"300\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Web request<\/text>\n  <text x=\"300\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Full path, needs decryption<\/text>\n\n  <rect x=\"400\" y=\"14\" width=\"176\" height=\"66\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"488\" y=\"40\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#6b4576\">Endpoint agent<\/text>\n  <text x=\"488\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Travels with the device<\/text>\n\n  <rect x=\"400\" y=\"96\" width=\"176\" height=\"66\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"488\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Email<\/text>\n  <text x=\"488\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Links and attachments<\/text>\n\n  <rect x=\"590\" y=\"52\" width=\"156\" height=\"72\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"668\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#1c267a\">Same rule<\/text>\n  <text x=\"668\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Different reach,<\/text>\n  <text x=\"668\" y=\"112\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">different cost<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Layer<\/th><th>What it can enforce<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a><\/td><td>Block or allow a whole domain, across every protocol, before any connection is opened<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/url-filtering\/\">URL filtering<\/a><\/td><td>Allow one page and refuse another on the same site, plus warn, log or apply a quota. Requires decryption for real depth<\/td><\/tr>\n    <tr><td>Endpoint agent<\/td><td>The same policy applied on the device, so it holds on a home network or a hotspot rather than only inside the office<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email filtering<\/a><\/td><td>Malicious links and attachments removed before delivery, which is where most harmful content actually arrives<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Secure web gateways bundle the middle two and add inspection of the response body. In a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a> architecture that gateway is the delivery vehicle. None of that changes the policy question underneath.<\/p>\n\n<h2 id=\"jobs\" class=\"c-sage\">Two jobs that get confused<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Question<\/th><th>Acceptable use<\/th><th>Threat blocking<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Purpose<\/td><td>Productivity, legal exposure, workplace conduct<\/td><td>Stopping malware, phishing and data theft<\/td><\/tr>\n    <tr><td>Owner<\/td><td>People or legal team<\/td><td>Security team<\/td><\/tr>\n    <tr><td>Typical categories<\/td><td>Gambling, adult content, streaming, social<\/td><td>Malware hosts, phishing pages, newly registered domains, command and control<\/td><\/tr>\n    <tr><td>Cost of a false block<\/td><td>An annoyed employee<\/td><td>The same, but the alternative is an incident<\/td><\/tr>\n    <tr><td>Cost of a miss<\/td><td>Wasted time or a conduct issue<\/td><td>A compromised device<\/td><\/tr>\n    <tr><td>Right default<\/td><td>Warn rather than block<\/td><td>Block outright<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Do not run both on one policy<\/p>\n  <p>Threat categories should be blocked silently and without exception, because nobody has a legitimate reason to reach a command and control server. Acceptable-use categories should mostly warn, because the judgement is contextual and a marketing team genuinely needs social platforms. Companies that apply one severity to both either block too much and generate a permanent exception queue, or loosen everything to stop the complaints and lose the threat blocking along with it.<\/p>\n<\/div>\n\n<h2 id=\"choose\" class=\"c-plum\">Choosing where to enforce<\/h2>\n\n<p>The right content filtering layer depends less on the feature list than on where your people actually work.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Situation<\/th><th>Where to enforce<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Fully remote or hybrid team<\/td><td>Endpoint agent. Network-level policy stops applying the moment someone leaves the office<\/td><\/tr>\n    <tr><td>Small team, threat blocking only<\/td><td>DNS filtering. Covers all protocols, deploys in hours, needs no certificates<\/td><\/tr>\n    <tr><td>Regulated acceptable-use obligation<\/td><td>URL filtering, because category evidence and per-user records are usually what the obligation requires<\/td><\/tr>\n    <tr><td>Need to block one path on an allowed service<\/td><td>URL filtering with decryption. Nothing shallower can distinguish two pages on the same domain<\/td><\/tr>\n    <tr><td>Most harmful content arrives by mail<\/td><td>Email filtering first. Filtering the web while leaving inbound mail unfiltered protects the wrong door<\/td><\/tr>\n    <tr><td>Contractor or unmanaged devices<\/td><td>None of these reach them. Restrict what those devices can access through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">private access<\/a> instead<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"fails\" class=\"c-sky\">Where content filtering fails<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Failure<\/th><th>What happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Over-blocking<\/td><td>Staff route around it with personal devices and hotspots, which removes visibility entirely rather than reducing risk<\/td><\/tr>\n    <tr><td>Encrypted DNS<\/td><td>Browsers resolving names through their own provider skip network policy silently, and nothing appears in the logs<\/td><\/tr>\n    <tr><td>Unmanaged devices<\/td><td>Contractor laptops and personal phones carry no agent, so the policy simply does not exist for them<\/td><\/tr>\n    <tr><td>Stale categories<\/td><td>New domains are uncategorised on the day they are used, which is exactly when a phishing site is most dangerous<\/td><\/tr>\n    <tr><td>Shared hosting<\/td><td>The malicious page sits on a platform you cannot block without blocking a service the business depends on<\/td><\/tr>\n    <tr><td>No exception process<\/td><td>Every block becomes a support ticket, and eventually someone widens the policy to stop the tickets<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The pattern in most of those is the same. Filtering that people experience as unreasonable does not get tightened, it gets bypassed, and a bypassed control produces neither protection nor evidence.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Content filtering runs inside the endpoint module rather than as a network appliance or a proxy you operate. That placement is the point: policy travels with the laptop, so it holds on a home network, in a coworking space or on a mobile hotspot, where anything configured at an office gateway stops applying the moment the device leaves.<\/p>\n\n<p>The layers around it come from the same stack rather than from four vendors. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> covers traffic that never touches a browser. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Inbound email security<\/a> handles the door most harmful content actually arrives through. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">Endpoint protection<\/a> deals with anything that does get downloaded, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">device control<\/a> governs what can be copied off, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a> covers what leaves.<\/p>\n\n<p>There is no break-and-inspect proxy and no certificate authority to distribute, which is a deliberate limit. If your requirement is per-path policy on decrypted traffic across a large managed estate, that is a gateway purchase. If it is enforceable acceptable-use and threat blocking that survives remote work, this is the shape that fits. Events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a>, and the records support the acceptable-use and malicious-code controls sampled under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Policy that survives leaving the office<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Content and DNS filtering enforced on the device, with email security, endpoint protection and data loss prevention behind them. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is content filtering?<\/summary>\n  <p>Restricting what people can reach from company devices and networks, covering both threat blocking and acceptable-use policy. It can be enforced at the name lookup, in the web request, on the endpoint or in email.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between content filtering and DNS filtering?<\/summary>\n  <p>Content filtering is the objective. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS filtering<\/a> is one way to achieve it, working at the domain level before any connection. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/url-filtering\/\">URL filtering<\/a>, endpoint agents and email filtering are the others.<\/p>\n<\/details>\n\n<details>\n  <summary>Should content filtering block social media?<\/summary>\n  <p>Usually warn rather than block. Whole teams have legitimate reasons to use those platforms, and a blanket block generates an exception queue that eventually gets widened. Reserve outright blocking for threat categories where no legitimate reason exists.<\/p>\n<\/details>\n\n<details>\n  <summary>Does content filtering work for remote staff?<\/summary>\n  <p>Only when enforcement sits on the device. Policy configured on an office network or gateway stops applying as soon as a laptop joins a home network or a hotspot, which for a distributed team is most of the time.<\/p>\n<\/details>\n\n<details>\n  <summary>Is content filtering required for compliance?<\/summary>\n  <p>No framework names it directly. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a> ask for protection against malicious code and for an enforced acceptable-use policy. Filtering with logs is a common way to evidence both.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dns-filtering\/\">DNS Filtering<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/url-filtering\/\">URL Filtering<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/email-security\/\">Email Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/device-control\/\">Device Control<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">DLP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sase\/\">SASE<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Content filtering is a policy, not a product. The same rule can be enforced in four different places, and choosing\u2026<\/p>\n","protected":false},"author":8,"featured_media":1215,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[617,610,615,616],"class_list":["post-1214","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-acceptable-use-policy-enforcement","tag-content-filtering","tag-content-filtering-vs-dns-filtering","tag-web-content-filtering"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1214","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1214"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1214\/revisions"}],"predecessor-version":[{"id":1216,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1214\/revisions\/1216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1215"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1214"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1214"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1214"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}