Certification status
GLS does not claim ISO 27001 certification at this time. Alignment refers to the use of ISO 27001 principles and control domains as a design and governance reference model rather than formal certification.
Purpose
This policy explains how GLS aligns its security and governance model with ISO 27001 and how this supports customers operating within ISO-aligned assurance frameworks.
Scope
This policy covers platform-level controls within GLS including security, continuity, access governance and audit capabilities.
ISO 27001 Annex A control alignment
A.5 — Information security policies
GLS maintains written governance policies including information security, data protection, business continuity and audit & traceability.
A.9 — Access control
- role-based access control
- tenant-scoped permissions
- traceability of sensitive operations
A.12 — Operations security
- controlled change and release
- logging of security-relevant events
- resilience and backup capability
A.16 — Information security incident management
Logging and audit trails support structured investigation and incident review processes.
A.17 — Business continuity management
GLS includes continuity controls, backup and recovery measures to help minimise operational disruption.
NIST Cybersecurity Framework alignment
GLS governance and platform controls are also consistent with the NIST Cybersecurity Framework. Alignment is summarised below:
- Identify — tenant isolation, scoped assets, governance
- Protect — RBAC, encryption, secure deployment controls
- Detect — logging and traceability across key actions
- Respond — audit evidence supports investigations
- Recover — backup and continuity mechanisms
This alignment supports customers who operate within ISO- or NIST-aligned security governance models. GLS does not assert formal certification or accreditation.
Customer responsibilities
Customers remain responsible for internal user management, lawful use of data, endpoint protection and their wider organisational compliance obligations.
Review
This policy is reviewed at least annually or when control objectives, threat conditions or regulatory expectations materially change.