Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Compliance

Control alignment for regulated file workflows

Glasswall CDR treats every inbound file as untrusted, then validates it against the published file specification and rebuilds it to a known-good standard before it crosses a trust boundary. Glasswall reports 100% of malicious files neutralised across 8.27 million tested, deterministic rebuild, not detection. Safeware ties that capability to the specific controls your assessor will test, and packages the evidence for review.

Alignment is documented at the control level. It does not substitute for IRAP assessment or ISO 27001 certification, and implies no blanket certification that Glasswall or Safeware does not hold.

Alignment references NIST CSF NIST 800-53 ISO 27001 ISM PSPF IRAP MAS TRM PDPA CSA CCoP

Framework alignment

How Glasswall CDR maps to the controls you are assessed against

01

NIST 800-53 / NIST CSF

Maps to SI-3 (malicious code protection), SC-7 (boundary protection), AC-4 (information flow enforcement) and AU-2/AU-12 (audit events and logging). Glasswall CDR rebuilds every file crossing the boundary; the per-file verdict record is the audit evidence the AU family asks for. Under the NIST CSF, this supports the PR.DS and PR.PT categories.

02

ISM / PSPF / Essential Eight

CDR strips and rebuilds active content before files reach the desktop or a classified domain. That reinforces two Essential Eight strategies, user application hardening and configuring Microsoft Office macro settings, and supports the ISM content-validation and content-conversion controls. Macro analysis (Powered by Safeware) inspects embedded macros and active content; Glasswall CDR enforces the rebuild. We document where this sits relative to PROTECTED-aligned environments, without claiming an IRAP assessment we have not completed.

03

MAS TRM / PDPA

For Singapore financial institutions, CDR aligns with the MAS TRM guidance on system security and network perimeter defence: untrusted files are rebuilt at the boundary rather than admitted on a detection verdict. Find & Redact removes named data patterns before files are stored or shared, supporting the PDPA Protection Obligation. Every verdict is logged for audit.

04

CSA Cyber Essentials / Cyber Trust (CCoP context)

For operators in Singapore's Critical Information Infrastructure regime, CDR supports the malware-protection and secure-configuration domains of the CSA marks and the file-handling expectations of the sectoral Codes of Practice (CCoP): inbound files are rebuilt to a known-good standard before they reach an operational network. Safeware maps the relevant clauses to the deployment in scope.

05

ISO 27001 / IRAP-assessable architecture

Safeware prepares the deployment evidence an assessor expects: architecture diagrams, trust-boundary mapping, operational procedures, the support model, exportable telemetry, and a documented control-responsibility matrix, what Glasswall enforces, what Safeware operates, and what the customer retains. IRAP is an assessment process, not a certification; the architecture is built to be assessable.

Cross-domain transfer

Moving files between security domains

Cross-domain and Raise-the-Bar (RTB) transfers carry the strictest file-handling requirements: content must be transformed to a known-good state, not merely scanned, before it crosses from a lower to a higher classification. Glasswall CDR rebuilds each file to the published specification at the transfer point, producing a deterministic, repeatable transformation an assessor can reason about. Glasswall reports 100% of malicious files neutralised across 8.27 million tested, no signature, sandbox detonation or verdict delay in the path. Safeware documents how the rebuild sits within a cross-domain or RTB pattern for the deployment in scope; it does not assert RTB accreditation that Glasswall or Safeware does not hold.

Technical controls by Glasswall; regional deployment and operations by Safeware.

Transfer point

Lower domainUntrusted files arrive for transfer
Glasswall CDR rebuildDeterministic transformation to the published specification
Higher domainOnly rebuilt, known-good content crosses

Per-file verdict record retained as assessment evidence.

Assurance pack

The evidence a regulated rollout ships with

Safeware delivers the assurance pack your security review and procurement teams will request, boundary map, policy map, telemetry specification and cutover runbooks, at architecture review, not after go-live.

Boundary mapWhere files enter, leave, and cross trust zones.
Policy mapAllow, warn, quarantine, block, release, and exception handling.
TelemetryVolume, verdict and error records, exportable to your SIEM for operations and audit.
RunbooksCutover, rollback, support escalation, and customer operations guidance.

Trusted where it matters

Deployed by the world's most security-conscious organisations

NATO NSA HM Government AUKUS Microsoft Oracle BAE Systems Beazley

Glasswall technology protects government, defence and intelligence communities worldwide. Across Asia-Pacific, Safeware delivers it to government, defence, financial services and critical-infrastructure organisations.

Book a demo

Plan your Glasswall deployment with Safeware

Share your operating context and file workflows. We'll map an implementation path for cloud, on-premises and isolated environments, with clear delivery milestones.