Purpose
This policy explains how GLS supports customers who are subject to the EU NIS2 Directive. It describes the platform security, continuity and governance controls that enable operators to demonstrate responsible management of digital infrastructure and operational data.
Scope
This policy applies to all GLS tenants, users and hosted environments, including development, staging and production workloads.
Principles
- Security-by-design rather than bolt-on controls
- Tenant isolation and least-privilege access
- Traceability and accountability for key actions
- Backup and continuity aligned to operational importance
- Clear governance responsibilities and oversight
Controls implemented in GLS
Access control
Access to GLS is tenant-scoped and role-based. Elevated permissions are explicitly granted. Authentication supports secure password management practices and can be extended to MFA-capable identity providers.
Tenant isolation
Operational and commercial data is logically separated by tenant. Access to data requires valid tenant context and authorisation.
Logging & traceability
Security-relevant actions are logged and retained so that operators can review activity and provide evidence to auditors or regulators.
Business continuity
GLS includes resilient architecture and backup processes designed to reduce operational disruption. Restoration procedures are tested and continuously improved.
Secure development & change management
Platform changes are deployed through controlled release processes, reducing the risk of unreviewed or unintended change.
Alignment with NIS2
This policy supports alignment with NIS2 requirements relating to access control, logging, continuity, risk management and governance. GLS does not replace an operator’s internal organisational responsibilities, but forms part of a defendable control framework.
Responsibilities
GLS is responsible for the design and operation of platform-level controls. Customers remain responsible for internal user permissions, operational use of the system and the accuracy of submitted data.
Review
This policy is reviewed at least annually, or sooner where material change occurs in platform design, regulation or risk exposure.