ENS Implementation: How to Comply with the Spanish National Security Scheme

ENS Implementation: How to Comply with the Spanish National Security Scheme

ENS implementation - Jaymon Security

1. Introduction

ENS implementation (Spanish National Security Scheme, Esquema Nacional de Seguridad) is the process by which a public-sector entity, or a company providing services to it, adapts its information systems to the requirements of Royal Decree 311/2022. ENS implementation is not an administrative formality: it is a risk management programme that affects people, processes and technology, and that requires a prior risk analysis performed with methodologies such as Magerit.

In this guide we walk through the phases of ENS implementation, from system categorization to the conformity audit, with real examples of the statement of applicability and an indicative timeline. If your organization needs help with this process, Jaymon Security supports companies and entities in the full ENS implementation, including the risk analysis and the required documentation.

2. What the ENS is and who it applies to

The Spanish National Security Scheme, currently regulated by Royal Decree 311/2022, is the set of principles and minimum security requirements that public administration information systems must comply with. Its objective is to create a homogeneous level of trust in the use of electronic means, protecting information according to its value and the services it supports.

The obligation of ENS implementation directly affects all public-sector bodies. But it has a cascade effect: private companies providing services to the Administration (developers, integrators, hosting or cloud providers) must also meet requirements of the scheme, because article 33 of the regulation obliges public entities to demand guarantees from their suppliers. In practice, a public tender with security requirements means your company needs ENS implementation to be able to compete.

The scheme is built on a set of principles — risk management, defence in depth, continuous improvement and incident management before reaction — that reappear in every requirement. Understanding these principles helps prioritize during ENS implementation: measures that support incident and continuity management are usually the first to deploy, because they reduce the most impactful risks and are the ones regulators check first in the conformity audit. Aligning the internal security roadmap with these principles makes the whole ENS implementation more efficient and avoids the classic error of deploying random technical controls without a plan.

2.1. Who is affected by ENS implementation in practice

Three scenarios should be distinguished. First, the public body that must adapt itself. Second, the supplier that must prove it provides services securely and in line with the scheme. And third, the private company that, without any relationship with the Administration, decides to adopt ENS implementation as a reference for good practices and as a competitive advantage. In all three cases the working methodology is the same and is based on risk analysis.

3. Risk analysis and system categorization

The starting point of ENS implementation is system categorization, which can be basic, medium or high. The category is determined by evaluating the impact of losing confidentiality, integrity, availability, authenticity and traceability of information and services. A wrong categorization causes either unnecessary spending (over-categorizing) or a compliance risk (under-categorizing).

The risk analysis is then performed with a recognized methodology, preferably Magerit. The analysis identifies the threats to each asset, calculates their impact and frequency of materialization, and determines the resulting severity. The result is cross-checked against the protection level required by the category. A simplified example of the kind of output this phase produces:

RISK ANALYSIS (extract, Magerit)
--------------------------------
Asset: [Dat] Customer database        Level: MEDIUM
Threat: [N.2] Operator error          Impact: 2  Frequency: 3  Risk: 6
Threat: [E.1] Unauthorized access     Impact: 4  Frequency: 2  Risk: 8
Threat: [A.6] Privilege abuse         Impact: 4  Frequency: 2  Risk: 8
Required protection level: HIGH

Fig. 1 – Example of a Magerit-style risk analysis output for ENS implementation.

The valuation of the security dimensions is decisive in ENS implementation: losing the confidentiality of personal data is not the same as losing the availability of an emergency service. That is why the categorization document must justify every value assigned to information and services, and the analysis must treat the dimensions separately. A common mistake is valuing only confidentiality and forgetting that, in many Administration systems, availability is the critical dimension. A rigorous approach reflects this prioritization in the selection of measures itself: continuity and redundancy measures are justified precisely by those values.

4. Statement of applicability and security measures

With the category and the risk analysis defined, ENS implementation moves to the statement of applicability (SoA): the document that links each measure of annex II of Royal Decree 311/2022 with the implementation status in the system, indicating whether it applies, whether it does not, and the reason. Measures are grouped into families: organizational (op), protection of information (mp.info), protection of services and systems (mp.sw, mp.com, mp.eq), continuity (mp.cont) and protection of facilities (mp.fis).

A typical extract of the statement of applicability during an ENS implementation could look like this:

STATEMENT OF APPLICABILITY (extract)
------------------------------------
[mp.com.1] Information security requirements     YES
[mp.com.2] Security of information systems       YES
[mp.com.3] Security of communications            YES
[mp.sw.1]  Lifecycle of information systems      YES
[mp.sw.2]  Development procedures                NO (services outsourced)
[mp.eq.1]  Identification and authentication     YES
[op.exp.1] External services management procedure  YES
[op.exp.2] Segregation of functions and tasks    YES
[op.exp.3] Monitoring of information systems     YES
[op.exp.4] Incident management                   YES

Fig. 2 – Extract of a statement of applicability with ENS measure codes.

It is common for many measures in the [op.exp] and [mp.sw] families to reveal gaps in this phase: non-existent incident management procedures, software development without security controls or external services without service level agreements. These gaps are corrected in the adaptation plan, which must prioritize measures according to the residual risk level.

The adaptation plan derived from the SoA must define, for each pending measure, the owner, the deadline and the evidence of implementation. In ENS implementation, evidence is precisely what the conformity audit will verify later: meeting minutes, configurations, access lists, incident records. Many organizations underestimate this and discover in the audit that measures were never really operational.

5. ENS implementation phases and timeline

ENS implementation is organized into phases that should be planned with measurable milestones. The following table summarizes the usual phases of a project for a medium-category system, with deliverables and indicative duration.

Phase Activities Deliverables Duration
1. Categorization Identification of information and services, security dimensions Categorization document 2-3 weeks
2. Risk analysis Asset inventory, threat valuation with Magerit Risk analysis report 3-4 weeks
3. Adaptation Statement of applicability, adaptation plan, measure deployment SoA, adaptation plan, implemented measures 3-6 months
4. Documentation Policies, procedures, security management instructions ENS documentation package 2-4 weeks (parallel)
5. Follow-up Self-assessment, status reports, periodic review Security status report Ongoing

The total time for a complete ENS implementation is usually between 6 and 12 months for medium-category systems, and can exceed one year for high-category systems with many services. The key to success is not to treat documentation as an end in itself: procedures are only worth anything if people know them and apply them.

In addition to the timeline, ENS implementation requires assigning concrete responsibilities from the start: the roles of system owner, security officer and information responsible, coordinated by a security committee. Without a clear assignment of these roles, deadlines slip, documentation becomes orphaned and the statement of applicability stops being alive. Remember that ENS implementation is not a technology project in the strict sense but a governance one: the technical component follows from the organizational one, not the other way around, and external suppliers must be formally integrated into the management of the system.

6. Self-assessment, status reports and audit

Once the measures are implemented, the entity must operate the system under a continuous improvement cycle. Royal Decree 311/2022 requires a security status report at least annually, based on the self-assessment of compliance with the statement of applicability. In addition, systems must undergo a conformity audit: every three years at minimum, and every two years for high-category systems. The audit is performed by a qualified entity or by the organization’s own accredited personnel.

It is important to understand the difference between self-assessment and audit: the former is internal and continuous; the latter is independent and verifies real conformity with the declared ENS implementation. When the audit detects deviations, a correction plan is drawn up with deadlines, the following year’s status report must reflect its follow-up. The security status report, one of the periodic obligations of ENS implementation, must feed on those data and include at least the status of the statement of applicability, the relevant incidents of the period and the follow-up of corrective measures; without these blocks it does not serve as an input for the audit or for continuous improvement. The result of the audit must also be documented and kept available for the competent authority for the required period, and serious deviations condition the following year’s status report.

7. Conclusion

ENS implementation is a demanding process, but perfectly manageable if approached with method: categorize correctly, analyse risks with Magerit, declare and deploy the right measures, and sustain a cycle of self-assessment and audit. For a company that works with the Administration, ENS implementation has become a commercial requirement and a differentiating advantage over competitors that have not yet tackled it. Plan in phases, document rigorously and do not leave follow-up until the end: conformity is a continuous state, not a one-off event.

Related articles: how to perform a company risk analysis with Magerit and data protection legislation and risk analysis.

To go deeper, consult Royal Decree 311/2022 in the BOE, the guides of CCN-CERT and the publications of ENISA.

If your organization needs to get up to date with the scheme, Jaymon Security helps companies and entities with ENS implementation using a practical approach: risk analysis, statement of applicability, documentation and preparation for the conformity audit.

Need help with ENS implementation?

At Jaymon Security, we help organizations protect their systems. From security audits to SIEM/SOC implementation, our expert team designs custom solutions.

Contact us for a free infrastructure assessment.

No puedes copiar el contenido

ENES