IBM NS1 Connect

IBM NS1 Connect

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

IBM NS1 Connect Security and Compliance: Enterprise DNS built for regulated industries

By Claire ODonovan posted 29 days ago

  

For organizations in regulated industries, DNS is part of the security perimeter. Financial services, banking, insurance, SaaS, government, and retail teams need DNS and traffic management services that can support strict security, privacy and compliance requirements without slowing the business down. 

 

At IBM NS1 Connect, security is embedded into every aspect of our platform and operational processes. We maintain a comprehensive security and compliance program that is independently audited and validated through internationally recognized certifications and third-party assessments. These certifications provide customers with confidence that IBM NS1 Connect follows industry best practices for information security, privacy protection, cloud security and operational governance.  

 

This article explains what those certifications mean in practical terms, how they map to cloud and privacy assurance and why they matter when DNS is part of a mission-critical operating environment. 

 

IBM NS1 Connect Security Certifications 

 

  • ISO 27001 - Information Security Management System (ISMS) 

  • ISO 27017 - Cloud-specific information security controls 

  • ISO 27018 - Protection of personally identifiable information in public cloud environments 

  • ISO 27701 - Privacy Information Management System 

  • SOC2® Type II – System and Organization Controls 2 

  • CSA STAR Level 2 Certification - Cloud Security Alliance 

 

Each certification is independently assessed by accredited third-party auditors and demonstrates our ongoing commitment to maintaining rigorous security and privacy standards. 

Globally Recognized Security Standards  

 

IBM NS1 Connect holds four ISO certifications that cover security management, cloud-specific controls and data privacy. Together, they provide globally recognized assurance that security and privacy risks are managed through documented controls, governance and independent review. 

 

ISO 27001- Information Security Management System 

 

ISO 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). It verifies that IBM NS1 Connect has implemented a comprehensive framework for identifying, managing and continuously improving information security risks across the organization.  

 

The certification evaluates controls across multiple areas, including: 

  • Organizational controls 

  • People controls 

  • Physical controls 

  • Technological controls 

With more than 90 security controls evaluated as part of regular independent audits, customers can be confident that information security risks are systematically managed through documented processes, governance and operational oversight.  

 

ISO 27017  Cloud Security Controls 

 

As cloud adoption continues to accelerate, organizations require additional assurance that cloud services are operated and managed securely. Building on ISO 27001, ISO 27017 introduces controls and guidance specifically designed for cloud environments. These controls address areas such as - Asset Management, Access Control with Network and Operations Security are all tailored to controls specific to cloud environments. For customers evaluating a cloud-native DNS provider, this certification provides assurance that goes beyond general information security and speaks directly to cloud risk. 

 

ISO 27018  Protection of Personal Identifiable Information in Public Clouds 

 

ISO 27018 focuses specifically on protecting personally identifiable information (PII) in public cloud environments. With data protection regulations proliferating worldwide, this certificate gives customers assurance that NS1 Connect has the controls and processes in place to safeguard personal data – a critical consideration for any regulated organization handling customer information.  

 

ISO 27701 - Privacy Information Management Systems 

 

Privacy has become a strategic priority for organizations navigating regulations and customer expectations around data protection. ISO 27701 extends information security management into privacy management by establishing a formal Privacy Information Management System (PIMS). This certification demonstrates that NS1 Connect has established governance, processes and controls to manage privacy risks and protect personal data throughout its lifecycle.  

 

SOC2® Type II – System and Organization Controls 2 

 

SOC2® Type II, created by the American Institute of Certified Public Accountants (AICPA), is one of the most widely recognized assurance reports for cloud and SaaS providers. Unlike a point-in-time assessment, a SOC2® Type II audit evaluates the effectiveness of security controls over an extended audit period. Independent auditors assess whether controls are operated consistently and effectively across the review period, providing customers with assurance that security practices are embedded into day-to-day operations. An annual assessment is conducted by an independent auditing organization. 

 

Cloud Security Alliance (CSA) – Security, Trust, Assurance and Risk (STAR)  

 

IBM NS1 Connect is certified to the Cloud Security Alliance’s STAR (Security, Trust, Assurance and Risk) program at Level 2 – currently the highest level requiring independent, third-party assessment. STAR Level 2 builds on ISO 27001 or SOC2 Type II, in addition to the Cloud Control Matrix (CCM), a security framework purpose-built for cloud service providers.  

 

For organizations evaluating SaaS providers, CSA STAR certification provides additional confidence that security practices align with established cloud security best practices.   

 

 

Enterprise-grade Security for Mission-Critical DNS 

 

DNS is one of the most critical services in modern digital infrastructure. It enables every application, transaction and customer interaction, making security, availability and resilience essential to business continuity.  

 

Our portfolio of internationally recognized security certifications demonstrates an ongoing commitment to information security, privacy and cloud security best practices. Through regular independent audits and continuous compliance, IBM NS1 Connect provides customers with the confidence that their DNS platform is backed by robust security governance and operational controls 

 

For organizations operating in regulated industries, these certifications help streamline vendor security assessments, support compliance and audit requirements, and reinforce trust in the security and resilience of critical infrastructure.  

 

At IBM NS1 Connect, security is more than a compliance requirement, it is a core principle embedded throughout our technology, operations and processes. By combining enterprise-grade DNS and traffic management with a comprehensive security and compliance program, we help organizations reduce risk, meet evolving regulatory expectations and operate with confidence in an increasingly complex digital landscape.  

 

Request Documentation 

 

If you require copies of our certifications as part of your vendor assessment, procurement process or compliance review, our team is happy to help. To request documentation, please complete this form and a member of the IBM team will assist you. 


#Technical
#TechnicalBlog

0 comments
18 views

Permalink