ISO 27001 for geospatial: what land agencies actually need to know
ISO 27001 is written to be domain-agnostic, which is its strength and, for a GIS team, its frustration. The Annex A controls talk about "information assets" and "access control" in the abstract, and it is on you to translate that into what it means for a tile cache, a WFS endpoint, or a cadastral layer. Auditors will accept a good translation; they will not do it for you.
Here is how the controls that matter most land in a geospatial context, and what evidence a certifier actually asks to see.
Access control is layer-level, not just app-level
The instinct is to secure the application login and call access control done. For spatial data that is not enough. A user authorised to see cadastral parcels may have no business seeing valuation overlays or restricted defence layers on the same map. Annex A access-control objectives, read properly, require permission at the layer and feature level, enforced at the data service, not just at the UI.
The risks that are specific to spatial platforms
- Tile cache poisoning: an unauthenticated or misconfigured cache serving stale or manipulated tiles as authoritative basemap.
- OGC endpoint authentication gaps: a WMS or WFS left open because "it is only a map service", exposing feature attributes and geometries.
- Layer permission leakage: metadata or GetCapabilities revealing the existence of restricted layers even when the data itself is protected.
- Bulk export as exfiltration: an unthrottled GetFeature or async export becoming a copy-the-whole-cadastre vector.
Mapping controls to evidence
Certification is an evidence exercise. For each control you claim, an auditor wants an artefact that proves it operates, not a policy that says it should. In practice the geospatial-specific asks are consistent, and preparing them in advance turns a stressful audit into a paperwork exercise.
- A data classification register that includes spatial layers, not just documents.
- Access-review logs showing who can see which layers, reviewed on a schedule.
- Authentication configuration for every OGC endpoint, including the ones you forgot were public.
- Rate-limit and audit-log evidence for bulk feature export.
Certification is a floor, not a ceiling
ISO 27001 proves you have a functioning information security management system, not that your platform is unbreakable. Treat it as the baseline a land agency can trust and build the geospatial-specific controls — layer permissions, endpoint authentication, export throttling — as the substance behind the certificate.
See Airfree Geospatial in action
Enterprise cadastre, LiDAR, earth observation, and AI on sovereign spatial infrastructure. Book a demo tailored to your data and jurisdiction.
Request a demo →