National Security Framework

Requirements of the National Security Framework (ENS)

Royal Decree 311/2022 regulates the National Security Scheme and the procedure for obtaining the ENS certificate. The National Security Scheme (ENS) sets out the principles and requirements that must be met by public administrations and private-sector providers handling information or digital services for such entities, with the aim of ensuring “information security” in e-government.

Basic principles of the ENS

The basic principles of the ENS (National Security Scheme) certificate are:

  1. Comprehensive security. Security must be considered holistically, taking into account people, processes, technologies, infrastructure and the organisational environment.
  2. Risk management. Security measures must be based on a continuous risk assessment, so that actions can be prioritised according to the impact and likelihood of threats.
  3. Prevention, detection and correction. The security system must be geared towards preventing incidents, but also towards detecting them at an early stage and correcting them effectively.
  4. Line of defence. A defence-in-depth model must be established, applying security measures in successive layers to hinder attacks and minimise their impact.
  5. Periodic reassessment. Systems must be reviewed regularly to ensure that security measures remain adequate in the face of changing risks and threats.
  6. Separation of duties: There must be a clear separation between those who use the systems, those who manage them and those who audit their operation, thereby avoiding conflicts of interest.
  7. Minimisation: only the necessary elements should be implemented in a system, and the information processed should be limited to what is strictly necessary, applying the principles of minimising the attack surface and data.
  8. Proportionality: measures must be proportionate to the level of risk and the value of the assets they protect.
  9. Accountability: every stakeholder (users, service managers, etc.) must be aware of and accountable for security within their area of responsibility.
  10. Documentation: measures, procedures and decisions must be properly documented to ensure traceability and facilitate audits.

Key organisational requirements include the ‘security policy’, ‘organisational coordination’ and ‘staff management’, which aim to ensure that roles and responsibilities are clearly defined and that employees are properly trained and made aware of cybersecurity and information security issues.

In terms of operational requirements, the ENS requires the implementation of measures such as ‘asset management’, ‘access control’, ‘protection against malware’ and ‘security incident management’. This can be integrated with your ISO certification documentation.

These controls are designed to protect systems and information throughout their entire lifecycle.

The ENS security requirements include aspects such as:

  • Communications protection to ensure the confidentiality, integrity and availability of information, through encryption, authentication, access control and monitoring, preventing unauthorised access and malicious tampering.
  • Backups. These ensure the availability and recovery of information in the event of incidents, through planned procedures, secure storage, regular testing and protection against unauthorised access or loss.
  • Protection of stored information. Ensures its confidentiality, integrity and availability through encryption, access control, audits, and physical and logical measures against unauthorised access or loss.
  • System resilience. Ensures system operation in the event of failures or attacks, through redundancy, continuity plans, regular testing and rapid recovery capabilities to maintain essential services.

Compliance with the ENS not only helps to minimise risks and protect your digital assets, but is also a “legal requirement” for doing business with the public sector. Adoption of the ENS is formalised through a “declaration of conformity” or a certificate issued by an accredited certification body.

FAQs: National Security Framework

What is the difference between ENS and ISO 27001?

The main differences between the National Security Framework (ENS) and ISO/IEC 27001 are:

  • With regard to scope and objective. The ENS is a Spanish regulatory framework governing the security of information systems in the public sector and among suppliers that handle data or provide services for it. To ensure the protection of information within public administrations and their suppliers, in compliance with Spanish legislation (primarily Law 40/2015 and Royal Decree 311/2022). It is mandatory for public administrations and companies providing services to them in Spain. The ISO 27001 standard sets out the requirements for an Information Security Management System (ISMS). It manages information risks in any type of organisation, across any sector and country. It is voluntary and applicable when an organisation wishes to certify its information security management.
  • Certification. To obtain the ENS certificate, a specific audit is required, along with a declaration of conformity or certificate of conformity issued by accredited bodies in accordance with the system’s categories.
    To obtain the ISO 27001 certificate, the ISO certification body must be accredited by bodies such as ENAC, UKAS, etc.
  • Complementary: compliance with ISO 27001 helps to meet ENS requirements (though not 100%). One strategy is to implement ISO 27001 as a foundation and then make the necessary adjustments for the Basic, Medium or High category of ENS.

Key factors contributing to information security vulnerabilities:

  • Failure to update systems: Out-of-date systems and applications are an easy target for hackers, who exploit known vulnerabilities to gain access to networks and sensitive data.
  • Weak passwords: Using simple passwords or reusing them across multiple accounts can compromise your company’s security. Strong passwords and multi-factor authentication are essential.
  • Phishing and scams: Phishing emails remain one of the most effective tactics for tricking employees and gaining unauthorised access. Cybersecurity training can help identify these attacks.
  • Uncontrolled access: Allowing indiscriminate access to critical data and systems increases the risk of data breaches. It is crucial to implement access control policies and role-based permissions.
  • Lack of a security culture: IT security is not solely the responsibility of the IT department; all employees must be made aware of and trained in how to protect the company’s digital assets.

The NIS2 Directive (EU Directive 2022/2555) has been introduced in response to the need to review and update existing European cybersecurity legislation. It broadens the scope of application, providing greater coverage for sectors and services of significant social and economic importance, classifying them as essential or important entities depending on the criticality of their sector, their size, or the type of service provided.

Companies must prepare to comply with the requirements of the directive by adapting their cybersecurity policies to the standards already defined at European level.