CybersecurityFramework

Spain ENS

Spain - National Security Framework

The National Security Framework (ENS) is Spain's national cybersecurity framework that defines security principles and controls for public sector organizations and their suppliers to protect information systems and ensure the confidentiality, integrity, availability, authenticity, and traceability of digital services.

Overview

The National Security Framework (Esquema Nacional de Seguridad - ENS) is Spain's national cybersecurity and information security framework that establishes the security principles, requirements, and measures for protecting information and digital services used by the public sector. Applicable to Spanish public administrations and organizations that provide services to them, the ENS provides a common framework to ensure the confidentiality, integrity, availability, authenticity, traceability, and preservation of information processed through electronic means. Established in 2010 and updated through Royal Decree 311/2022, the framework adopts a risk-based approach to cybersecurity and requires organizations to implement appropriate organizational, operational, and technical security controls. The ENS aims to strengthen trust in government digital services, improve cyber resilience, and ensure the secure management of public sector information systems.

Related in Cybersecurity

CybersecurityStandard

NDIS Practice Standards and Quality Indicators v4

The NDIS Practice Standards and Quality Indicators v4 is Australia's quality and compliance framework for registered NDIS providers, defining the standards and quality indicators required to deliver safe, person-centred, and high-quality disability supports and services.

NDIS Quality and Safeguards Commission β€’ Australia β€’ v4

View details
CybersecurityStandard

NDIS SIL Module β€” NDIS Supported Independent Living Module

The NDIS Supported Independent Living (SIL) Module is a supplementary NDIS Practice Standards module that sets quality and safety requirements for providers delivering Supported Independent Living services, ensuring participants receive person-centred supports that promote independence, choice, inclusion, and wellbeing.

NDIS Quality and Safeguards Commission β€’ Australia

View details
CybersecurityStandard

CCC-2: 2024 β€” Cloud Cybersecurity Controls

The Cloud Cybersecurity Controls (CCC – 2: 2024) define minimum cybersecurity requirements for cloud computing services used by Cloud Service Providers (CSPs) and Cloud Service Tenants (CSTs) in Saudi Arabia. The controls aim to enhance national cybersecurity goals and mitigate cyber risks.

National Cybersecurity Authority (NCA) β€’ Saudi Arabia β€’ v2: 2024

View details
CybersecurityStandard

OTCC-1:2022 β€” Operational Technology Cybersecurity Controls

The Operational Technology Cybersecurity Controls (OTCC-1:2022), developed by Saudi Arabia’s National Cybersecurity Authority (NCA), establish minimum cybersecurity requirements for Operational Technology (OT) and Industrial Control Systems (ICS) environments. The framework aims to protect critical infrastructure from cyber threats and enhance operational resilience, safety, and security. OTCC consists of 4 domains, 23 subdomains, 47 controls, and 122 sub-controls, with requirements categorized across three control levels (L1, L2, and L3) based on facility criticality and risk.

National Cybersecurity Authority (NCA) β€’ Saudi Arabia β€’ v2022

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks β€” automatically.

Book your strategy call